sloh7[.]ru
“KRAKEN”
ملخص الأدلة
Analysis of sloh7.ru shows an active high‑risk phishing infrastructure first observed on April 30, 2026. The domain was registered through the REGRU‑RU registrar and resolves to the Cloudflare‑hosted address 104.21.71.87, using the nameservers kristin.ns.cloudflare.com and rodrigo.ns.cloudflare.com. VirusTotal has recorded a single positive detection out of 91 security vendors, indicating that at least one scanner identified malicious behavior. The domain currently appears on one external security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that threat intelligence communities consider it malicious.
No additional public reputation services, Safe Browsing entries, or OTX tags were supplied, so the broader ecosystem visibility remains limited. The sparse detection footprint suggests a low‑profile campaign that relies on the reputation of Cloudflare’s CDN to obscure origin, a technique commonly observed in recent phishing operations. Defenders should add sloh7.ru to proxy and firewall deny lists, monitor DNS queries for the domain and its associated Cloudflare nameservers, and enforce strict email filtering for messages containing links to the domain.
Given the single vendor flag, continuous re‑scanning of the domain on multi‑engine services is advisable to capture any escalation in detection rates. Incident response teams should treat any credential or payment requests linked to this domain as malicious, isolate affected endpoints, and conduct forensic analysis to uncover potential credential harvesting. Until further intelligence becomes available, the domain should be considered hostile and blocked at the network perimeter.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
أول تسجيل
أول قيمة محفوظة: يمكن الوصول إليه
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of sloh7.ru · checked Aug 6, 2026
تحليل إعدادات الموقع
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب