Lompat ke laporan keamanan
Checked 09/08/2026 Ref F012AB2E

MALICIOUS — CRITICAL

sendit[.]sh

This domain is flagged as a high-risk credential theft operation targeting users through fraudulent login portals.

100/100 evidence score · Critical
VirusTotal
20/92
Blocklists
1 · CryptoFirewall
Ketersediaan
Terakhir diketahui aktif · HTTP 200
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 20. Daftar blokir publik yang melaporkan kecocokan: 1. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Jump to section
Ringkasan laporan

sendit.sh — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 20/92 (ADMINUSLabs, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, Certego); 1 external blocklist match (CryptoFirewall); PhishDestroy score 100/100.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Analysis

Ref F012AB2E

This domain is flagged as a high-risk credential theft operation targeting users through fraudulent login portals. Analysis indicates sendit.sh employs social engineering tactics to trick victims into submitting sensitive authentication details, which are then exfiltrated to attacker-controlled infrastructure. The threat type is specifically credential theft, not generic phishing, with indicators suggesting a focus on corporate or financial account compromise. Infrastructure analysis reveals the domain was registered on May 15, 2026, an anomalous future date likely intended to evade detection or mislead investigators. It resolves to IP address 37.187.78.41, hosted by a French provider, and uses a Let's Encrypt SSL certificate (R13). VirusTotal detection shows 21 out of 95 security vendors flagging the domain as malicious. The domain appears on two security blocklists and is actively blocked by at least two threat intelligence feeds. The SSL certificate, while providing encryption, is commonly abused in phishing campaigns to lend false legitimacy to fraudulent sites. Mitigation requires immediate action to prevent credential harvesting. Network-level blocking of the domain and its resolving IP (37.187.78.41) should be implemented across firewalls, DNS filters, and endpoint protection systems. Security teams should monitor for any attempts to access sendit.sh or related infrastructure, particularly from corporate networks. Users who may have interacted with the domain should be instructed to reset credentials for any accounts entered on the site, using multi-factor authentication where available. Organizations should also review logs for connections to the IP address and domain, as this may indicate successful compromise or ongoing reconnaissance activity.

VirusTotal
VirusTotal
20 det.
OTX references
Sertifikat TLS
Kedaluwarsa atau belum diverifikasi -3d
Usia
3 mo New
Status terpantau
Terakhir diketahui aktif 200
PhishDestroy
Daftar Hapus
Terdaftar
Cakupan data12 recorded checks
VirusTotal 20 / 92 URLQuery tidak diperiksa PhishStats tidak diperiksa OTX 3 community references CF Radar no data URLScan capture not submitted URLScan verdict putusan tidak tersedia Pemblokiran DNS tidak diperiksa TLS Kedaluwarsa atau belum diverifikasi WHOIS 3 mo old Tangkapan layar belum terekam Rantai pengalihan tidak diselidiki

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
7/9

Status Daftar Blokir Publik

Intelijen Domain

Domain
Server / ASN nginx · AS16276 OVH SAS
Reputasi IP abuse score 0/100 0 reports checked 13/07/2026
Alamat IP 37.187.78.41 FR
LokasiFR Roubaix, FR
JaringanAS16276 · OVH SAS
PendaftaranDibuat 15/05/2026 (85d · New)
Status HTTP200
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi15/06/2026
TLS Fingerprint
TLS Observationvalid from 09/05/2026scanned 22/05/2026
TLS SAN Domainswww.sendit.sh
Favicon Hash
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

20 / Vendor keamanan 92 menandai domain ini
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
ArcSight Threat Intelligence
BitDefender
Certego
Chong Lua Dao
Cluster25
CRDF
CyRadar
ESET
ESTsecurity
Emsisoft
Forcepoint ThreatSeeker
G-Data
Gridinsoft
Lionic
SOCRadar
Sophos
Viettel Threat Intelligence
VIPRE
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri
Sematkan Laporan IniRead-only HTML widget
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/sendit.sh"
  title="PhishDestroy threat report for sendit.sh"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>