Перейти к отчёту о безопасности
Checked 09.08.2026 Ref F012AB2E

MALICIOUS — CRITICAL

sendit[.]sh

This domain is flagged as a high-risk credential theft operation targeting users through fraudulent login portals.

100/100 evidence score · Critical
VirusTotal
20/92
Blocklists
1 · CryptoFirewall
Доступность
Последний известный активный · HTTP 200
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 20. Публичные черные списки, сообщающие о совпадении: 1. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

sendit.sh — Последний известный активный (HTTP 200). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 20/92 (ADMINUSLabs, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, Certego); 1 external blocklist match (CryptoFirewall); PhishDestroy score 100/100.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref F012AB2E

sendit.sh credential theft domain – high-risk phishing site

sendit.sh is a high-risk credential theft domain flagged by 21/95 vendors. Active FR-hosted site impersonates login portals to harvest user data.

This domain is flagged as a high-risk credential theft operation targeting users through fraudulent login portals. Analysis indicates sendit.sh employs social engineering tactics to trick victims into submitting sensitive authentication details, which are then exfiltrated to attacker-controlled infrastructure. The threat type is specifically credential theft, not generic phishing, with indicators suggesting a focus on corporate or financial account compromise. Infrastructure analysis reveals the domain was registered on May 15, 2026, an anomalous future date likely intended to evade detection or mislead investigators. It resolves to IP address 37.187.78.41, hosted by a French provider, and uses a Let's Encrypt SSL certificate (R13). VirusTotal detection shows 21 out of 95 security vendors flagging the domain as malicious. The domain appears on two security blocklists and is actively blocked by at least two threat intelligence feeds. The SSL certificate, while providing encryption, is commonly abused in phishing campaigns to lend false legitimacy to fraudulent sites. Mitigation requires immediate action to prevent credential harvesting. Network-level blocking of the domain and its resolving IP (37.187.78.41) should be implemented across firewalls, DNS filters, and endpoint protection systems. Security teams should monitor for any attempts to access sendit.sh or related infrastructure, particularly from corporate networks. Users who may have interacted with the domain should be instructed to reset credentials for any accounts entered on the site, using multi-factor authentication where available. Organizations should also review logs for connections to the IP address and domain, as this may indicate successful compromise or ongoing reconnaissance activity.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
20 det.
OTX references
Сертификат TLS
Просрочен или не проверен -3d
Возраст
3 mo New
Зафиксированный статус
Последний известный активный 200
PhishDestroy
DestroyList
В списке
Охват данных12 recorded checks
VirusTotal 20 / 92 URLQuery не проверено PhishStats не проверено OTX 3 community references CF Radar no data URLScan capture not submitted URLScan verdict вердикт недоступен DNS-блокировки не проверено TLS Просрочен или не проверен WHOIS 3 mo old Снимок экрана не зафиксировано Цепочка перенаправлений не исследовано

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
7/9

Статус в публичных блок-листах

Аналитика доменов

Домен
Сервер / ASN nginx · AS16276 OVH SAS
Репутация IP abuse score 0/100 0 reports checked 13.07.2026
IP-адрес 37.187.78.41 FR
ГеолокацияFR Roubaix, FR
СетьAS16276 · OVH SAS
Обратный поиск IPviewdns.info → rapiddns.io →
РегистрацияСоздано 15.05.2026 (85d · New)
Статус HTTP200
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено15.06.2026
TLS Fingerprint
TLS Observationvalid from 09.05.2026scanned 22.05.2026
TLS SAN Domainswww.sendit.sh
Favicon Hash
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

20 / Поставщики средств безопасности 92 отметили этот домен
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
ArcSight Threat Intelligence
BitDefender
Certego
Chong Lua Dao
Cluster25
CRDF
CyRadar
ESET
ESTsecurity
Emsisoft
Forcepoint ThreatSeeker
G-Data
Gridinsoft
Lionic
SOCRadar
Sophos
Viettel Threat Intelligence
VIPRE
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/sendit.sh"
  title="PhishDestroy threat report for sendit.sh"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>