# live.slon.app — SUSPICIOUS > live.slon.app is linked to generic phishing targeting user credentials. VirusTotal shows 0/95 detections. Check the full report for details. ## Summary The domain live.slon.app has been identified as potentially involved in a generic phishing scam specifically targeting user credentials, a common tactic known as credential harvesting. There is no public evidence linking this domain to any known brand or drainer kit at this time, but the nature of the threat suggests it aims to deceive users into divulging sensitive personal information. PhishDestroy classifies this as under investigation due to ongoing analysis of its threat characteristics. Technical data shows that live.slon.app resolves to IP address 35.156.120.189 and holds a Let's Encrypt SSL certificate, which can lend false credibility to phishing attempts. VirusTotal currently reports 0 detections out of 95 antivirus engines, indicating it is not yet flagged by mainstream security products. The domain's registrar information and creation date were not provided, but Google Safe Browsing (GSB) status and blocklist counts remain unreported, suggesting it is either newly active or under the radar of automated defense systems. At present, live.slon.app remains active and classified as under investigation. Security teams should monitor for changes in detection rates or inclusion on blocklists. Users are advised to avoid interacting with this domain, especially refraining from entering any credentials. Organizations should consider blocking the associated IP address and domain at network perimeters. Continued surveillance is recommended until conclusive risk assessments can be confirmed and appropriate mitigation steps are implemented. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 35.156.120.189 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/2cc4772a-26dc-4418-8aef-a1a535c575ea - PhishDestroy: https://phishdestroy.io/domain/live.slon.app/ - LLM endpoint: https://phishdestroy.io/domain/live.slon.app/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/live.slon.app/ Last updated: 2026-03-28