MALICIOUS — CRITICAL
sendit[.]sh
This domain is flagged as a high-risk credential theft operation targeting users through fraudulent login portals.
- VirusTotal
- 20/92
- Blocklists
- 1 · CryptoFirewall
- Ketersediaan
- Terakhir diketahui aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
sendit.sh — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 20/92 (ADMINUSLabs, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, Certego); 1 external blocklist match (CryptoFirewall); PhishDestroy score 100/100.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
This domain is flagged as a high-risk credential theft operation targeting users through fraudulent login portals. Analysis indicates sendit.sh employs social engineering tactics to trick victims into submitting sensitive authentication details, which are then exfiltrated to attacker-controlled infrastructure. The threat type is specifically credential theft, not generic phishing, with indicators suggesting a focus on corporate or financial account compromise. Infrastructure analysis reveals the domain was registered on May 15, 2026, an anomalous future date likely intended to evade detection or mislead investigators. It resolves to IP address 37.187.78.41, hosted by a French provider, and uses a Let's Encrypt SSL certificate (R13). VirusTotal detection shows 21 out of 95 security vendors flagging the domain as malicious. The domain appears on two security blocklists and is actively blocked by at least two threat intelligence feeds. The SSL certificate, while providing encryption, is commonly abused in phishing campaigns to lend false legitimacy to fraudulent sites. Mitigation requires immediate action to prevent credential harvesting. Network-level blocking of the domain and its resolving IP (37.187.78.41) should be implemented across firewalls, DNS filters, and endpoint protection systems. Security teams should monitor for any attempts to access sendit.sh or related infrastructure, particularly from corporate networks. Users who may have interacted with the domain should be instructed to reset credentials for any accounts entered on the site, using multi-factor authentication where available. Organizations should also review logs for connections to the IP address and domain, as this may indicate successful compromise or ongoing reconnaissance activity.
Cakupan data12 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.