Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@cosmotown.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
sendxvysd[.]com
“sendxvysd.com/”
sendxvysd.com — असत्यापित. ब्रांड प्रतिरूपण: Microsoft; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 88/100. रजिस्ट्रार: COSMOTOWN.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis indicates that the domain sendxvysd.com was registered on 11 March 2026 through COSMOTOWN, INC. and is hosted on the Ultahost, Inc. network (AS214036) in the Netherlands, resolving to the IPv4 address 192.142.54.88. The authoritative nameservers ns1.hostcreed.com and ns2.hostcreed.com resolve to the same hosting provider, confirming that the infrastructure is supplied by Hostcreed. The site employed a publicly trusted Let's Encrypt certificate (R12) and supported HTTP/3, suggesting recent deployment of modern web stack components.
Passive scans identified PHP, Bootstrap, LiteSpeed, and third‑party libraries such as jsDelivr, jQuery CDN, jQuery and Popper, which are commonly used in automated phishing kits. Threat intelligence sources have flagged the domain as a generic phishing vector. One of ninety‑five VirusTotal scanners raised an alert, and the domain appears on a single blocklist, specifically PhishDestroy. The page title returned by the server is the literal string “sendxvysd.com/”, providing no additional context about the intended target or lure.
No further evidence of brand impersonation, credential‑harvesting forms, or malicious payloads has been disclosed, and the site is currently taken offline, limiting immediate exposure. Uncertainty remains regarding the content that was served while the domain was active, the scale of any phishing campaign, and whether additional infrastructure (such as command‑and‑control servers or credential‑harvesting endpoints) was associated with the same IP range. Defenders should continue to block traffic to 192.142.54.88, add sendxvysd.com to internal denylists, and monitor for re‑registration or similar hostcreed.com name server usage. Correlation with other recent domains created in the same month may reveal a pattern, and any future HTTP or DNS queries for the domain should be logged for forensic analysis.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 8 identified
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Free public CDN for open-source projects, serving files from npm and GitHub.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of sendxvysd.com · checked Mar 11, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260311-0BB5AD Recipient: abuse@cosmotown.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।