الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

slonn3to[.]ru

“slon3.to — интернет-магазин туристического снаряжения в Москве.”

حكم التهديد عالية 56/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 2/94 نوع الاحتيال: Generic Phishing
16/03/2026 1 Report Sent
ملخص التقرير

slonn3to.ru — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 2/94 (Gridinsoft, SOCRadar); PhishDestroy score 56/100. مسجّل النطاق: REGRU-RU.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
مرتفع
المرجع
3C87B0A9
الدرجة
56/100

Analysis of slonn3to.ru indicates it operated as a fraudulent online storefront targeting Russian-speaking consumers under the guise of a Moscow-based outdoor gear retailer. The domain was registered on March 7, 2026, through REGRU-RU, a registrar frequently associated with phishing infrastructure. Infrastructure analysis reveals the site was hosted on IP 81.91.178.10, geolocated in the Netherlands under AS204601 (NovoServe B.V.), with nameservers ns1.reg.ru and ns2.reg.ru. No SSL certificate was present, increasing the risk of credential interception.

The page title, 'slon3.to — интернет-магазин туристического снаряжения в Москве,' explicitly positioned the site as an e-commerce platform for camping equipment, though no legitimate brand affiliation or product inventory was verified. Security vendors flagged the domain on July 25, 2026, with 2 of 94 engines on VirusTotal detecting malicious activity, while PhishDestroy and one additional blocklist had already classified it as abusive. The site was taken offline by the report date, though its prior use of DDoS-Guard (a service often leveraged to obscure hosting origins) suggests an intent to evade takedowns. Gridinsoft assigned a trust score of 0/100, reflecting high-risk characteristics.

Defenders should treat this domain as part of a broader phishing campaign targeting payment or personal data under the pretense of retail transactions. While the exact content and payment mechanisms remain unanalyzed, the combination of a fabricated storefront, lack of encryption, and hosting on bulletproof infrastructure aligns with credential-harvesting or fraudulent order schemes. Network defenders are advised to block the domain and IP, monitor for related registrations under REGRU-RU, and alert users who may have interacted with the site prior to its takedown.

VirusTotal
VirusTotal
2 det.
شهادة TLS
Let's Encrypt
العمر
5 mo
الحالة المرصودة
المحتوى غير متوفر 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات VirusTotal 2 / 94 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 14 تم الفحص — لا يوجد حظر TLS valid certificate, 80d WHOIS 5 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/12

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN ddos-guard · AS204601 PODAON NovoServe B.V., NL
سمعة عنوان IP abuse score 5/100 5 reports checked 14/07/2026
مسجّل النطاق REGRU-RU RU(RU)
عنوان IP 81.91.178.10 NL
الموقع الجغرافيNL Amsterdam, NL
الشبكةAS204601 · NovoServe B.V.
التسجيلتم إنشاؤه 07/03/2026 (160d)
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 37 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف16/03/2026
DOM Analysisanalyzed 24/03/2026score 56/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://slonn3to.ru/
خوادم الأسماءns1.reg.runs1.reg.ru.ns2.reg.runs2.reg.ru.
TLS Observationscanned 26/05/2026
Case ID
عنوان الصفحة
slon3.to — интернет-магазин туристического снаряжения в Москве.
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 80 days

الاستخبارات الجنائية الرقمية

External Scripts 1
https://performance.radar.cloudflare.com/beacon.js
التقنيات · 2 identified
PHP
Programming languages

Server-side scripting language designed for web development.

DDoS-Guard
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

2 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
Gridinsoft
SOCRadar
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of slonn3to.ru · checked Mar 16, 2026

100
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
0.76s
Largest Contentful Paint
CLS
0.027
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.89s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260316-74BF41 Recipient: abuse@server-panel.net
Page title stored with report: slon3.to — интернет-магазин туристического снаряжения в Москве.
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 32.7 KB
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/slonn3to.ru"
  title="PhishDestroy threat report for slonn3to.ru"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>