slon2----at---at[.]ru
“Slon2.at â инÑеÑнеÑ-магазин наÑÑолÑнÑÑ Ð¸Ð³Ñ Ð¸ головоломок …”
Zusammenfassung der Beweislage
Analysis of the domain slon2----at---at.ru indicates active credential phishing infrastructure targeting Russian-speaking users. The domain, registered on March 28, 2026, resolves to IP address 168.100.8.206, hosted in the Netherlands under ASN associated with BL Networks. The page returns an HTTP 200 status and presents a localized storefront in Russian, titled 'Slon2.at — интернет-магазин настольных игр и головоломок с доставкой по России,' designed to mimic a legitimate online retailer. The use of a Let's Encrypt SSL certificate (serial E7) provides HTTPS encryption, increasing the appearance of legitimacy to potential victims. Current detection metrics show limited but clear malicious classification. Two out of 95 security vendors on VirusTotal flag the domain as malicious, and it appears on one security blocklist. Additionally, the domain is referenced in one AlienVault OTX threat intelligence pulse, suggesting prior observation in phishing campaigns. The domain's Gridinsoft trust score of 0/100 further supports its classification as high-risk. While the exact phishing kit or brand impersonation is not confirmed, the combination of recent registration, low detection but consistent blocking, and localized content indicates a targeted campaign. Defenders should treat this domain as an active threat. The infrastructure remains operational as of July 12, 2026, and continues to serve content. Network-level blocking is recommended, particularly for organizations with Russian-speaking users or those in the retail or gaming sectors. Monitoring for connections to 168.100.8.206 and correlating with endpoint logs for credential access or unusual checkout behavior may help identify compromised users. Given the domain's presence on only one blocklist, broader detection coverage may be limited, so proactive hunting using the domain, IP, and SSL certificate fingerprint is advised.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of slon2----at---at.ru · checked Mar 28, 2026
Analyse der Website-Konfiguration
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt