الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 4. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

slon-avto[.]ru

“Российский производитель автокомпонентов”

حكم التهديد حرجة 76/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 4/91
OTX: 1 ref 15/06/2026
ملخص التقرير

slon-avto.ru — لم يتم التحقق منها. ملخص الأدلة: VirusTotal 4/91 (Chong Lua Dao, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
565BDDBD
الدرجة
76/100

The domain slon-avto.ru was registered on March 28, 2026 and currently returns HTTP 200 with the page title "Российский производитель автокомпонентов". The site is served over HTTPS using a Let’s Encrypt R12 certificate, which is valid and automatically renewed, suggesting a legitimate‑looking front end. The content mismatch between the automotive component theme and the observed phishing behavior forms the basis for the generic_phishing classification.

Infrastructure analysis shows the domain resolves to IP address 193.107.236.86, hosted within the NetAngels.RU network in Yekaterinburg, Russia, and appears to be a Rostelecom data centre. The host carries a Gridinsoft trust score of 0 out of 100, indicating a highly untrusted reputation. The same IP is listed on a single security blocklist and has been flagged by PhishDestroy, confirming that external defenders have already taken mitigation steps.

Threat intelligence indicates the domain appears in one AlienVault OTX pulse, but no detections are recorded on VirusTotal (0 of 95 scanners). This lack of detections does not imply safety; rather, it reflects the early stage of the campaign. The absence of malware signatures, combined with the clean VirusTotal profile, leaves the exact payload or credential‑harvesting mechanisms uncertain. The primary indicator of malicious intent is the domain’s appearance on a phishing‑specific blocklist and the mismatched branding presented to potential victims.

Defenders are advised to block slon-avto.ru at the DNS and firewall levels, monitor outbound connections to the associated IP, and incorporate the IP address into intrusion‑detection signatures. Continuous observation of traffic to this host is recommended to capture any evolving payloads. Organizations should also educate users about unexpected automotive‑industry communications, as the domain’s legitimate‑sounding title may be leveraged to increase trust among targeted recipients.

VirusTotal
VirusTotal
4 det.
OTX references
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -71d
العمر
5 mo
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 4 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX 1 community reference رادار CF no data URLScan capture not submitted URLScan verdict التقييم غير متاح حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 5 mo old لقطة شاشة لم يتم تسجيله سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
6/8

حالة قوائم الحظر العامة

معلومات النطاق

النطاق
الخادم / ASN nginx/1.14.1 · AS44128 Internet-Pro LLC
سمعة عنوان IP abuse score 0/100 0 reports checked 13/08/2026
عنوان IP 193.107.236.86 RU
الموقع الجغرافيRU Yekaterinburg, RU
الشبكةAS44128 · NetAngels.RU network in Yekaterinburg (Rostelecom DataCenter)
التسجيلتم إنشاؤه 28/03/2026 (139d)
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف15/06/2026
TLS Fingerprint
TLS Observationvalid from 07/03/2026scanned 23/04/2026
TLS SAN Domainsslon.test-1pos.ruwww.slon-avto.ruwww.slon.test-1pos.ru
Favicon Hash
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

4 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
Chong Lua Dao
CRDF
Gridinsoft
SOCRadar
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of slon-avto.ru · checked Mar 28, 2026

83
Needs Work
Performance
FCP
2.71s
First Contentful Paint
LCP
3.69s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
4.14s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/slon-avto.ru"
  title="PhishDestroy threat report for slon-avto.ru"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>