# 1slon3to.ru — SUSPICIOUS > WARNING: 1slon3to.ru is a fake login phishing domain harvesting credentials. Only 0 of 95 VirusTotal vendors flagged this yet. ## Summary 1slon3to.ru is a currently active credential phishing domain designed to harvest user login details. Investigations confirm this domain is engaged in generic phishing activity with a focus on impersonating legitimate login portals to capture credentials. Security teams have classified this domain as active and under continuous monitoring due to its potential impact on user security. This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan. It was registered through REGRU-RU on March 07, 2026, and resolves to the IP address 81.91.178.10. The domain utilizes a Let's Encrypt SSL certificate, which may contribute to a false sense of legitimacy. Despite the absence of detections on VirusTotal, the domain remains untrusted and is actively being reviewed for inclusion in blocklists. Users are strongly advised to avoid interacting with 1slon3to.ru or entering any credentials. Security teams should monitor network traffic for connections to the associated IP address 81.91.178.10. Verify the safety of this domain and similar sites using PhishDestroy’s real-time database before proceeding with any actions. Immediate reporting is recommended if this domain has been encountered in any suspicious contexts. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-07 02:28:11 - Registrar: REGRU-RU - IP: 81.91.178.10 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/b04df722-f644-4859-9d3e-6d628fba1f49 - PhishDestroy: https://phishdestroy.io/domain/1slon3to.ru/ - LLM endpoint: https://phishdestroy.io/domain/1slon3to.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/1slon3to.ru/ Last updated: 2026-03-28