# 5slon-5cc.ru — SUSPICIOUS > 5slon-5cc.ru hosts a credential theft phishing campaign with 0/95 VirusTotal detections and recent domain registration. Users should avoid interaction. ## Summary The domain 5slon-5cc.ru is currently involved in a credential theft phishing scheme. This means the site attempts to trick visitors into revealing sensitive login credentials, such as usernames and passwords, which can be used for identity theft or unauthorized account access. While the attack specifics are still under investigation, the core risk is the potential compromise of personal or financial information. This domain was registered recently on March 24, 2026, through the REGRU-RU registrar, indicating a newly created threat likely aiming to evade detection. Although VirusTotal reports 0 out of 95 engines detecting malicious content, this low detection rate is common for freshly deployed phishing domains before widespread reporting. The domain resolves to IP address 209.141.42.45 and uses a Let's Encrypt SSL certificate, which attackers often leverage to lend a false sense of security to their fake sites. If you have visited 5slon-5cc.ru or entered any credentials, immediately change your passwords for any accounts that may be at risk. Enable multifactor authentication where available to add a layer of protection. Avoid clicking links or providing data on unfamiliar domains, especially those registered recently with no reputation. Monitor your accounts for suspicious activity and report any fraudulent incidents to your service providers promptly. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-24 10:12:50 - Registrar: REGRU-RU - IP: 209.141.42.45 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/af79793e-ac4e-4fe4-8fb9-e0d84b9403a4 - PhishDestroy: https://phishdestroy.io/domain/5slon-5cc.ru/ - LLM endpoint: https://phishdestroy.io/domain/5slon-5cc.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/5slon-5cc.ru/ Last updated: 2026-03-28