# slon--1------at.ru — SUSPICIOUS > PhishDestroy identifies slon--1------at.ru as an active phishing site posing as a generic platform. Blocked by Hagezi, registered March 16, 2026, this domain. ## Summary PhishDestroy has identified an active phishing threat associated with the domain slon--1------at.ru. This domain is designed to mimic legitimate platforms, tricking users into entering sensitive information such as login credentials or financial details. The site leverages deceptive tactics, including the use of a recently registered domain and a free SSL certificate from Let's Encrypt, to appear trustworthy. Users should remain cautious of unsolicited links or unexpected login prompts, as these are common vectors for such attacks. This domain was flagged by security researchers and added to the Hagezi blocklist, indicating it has been confirmed as malicious. The domain slon--1------at.ru was registered on March 16, 2026, through REGRU-RU, a registrar known for domain registration services. It resolves to the IP address 46.254.20.193 and is currently detected by 1 out of 95 security vendors on VirusTotal. Its recent creation and low detection rate highlight the evolving nature of phishing campaigns, which often exploit newly registered domains before widespread recognition occurs. If you have visited slon--1------at.ru or entered any information on the site, take immediate action to secure your accounts. Change passwords for any services where you used the same credentials, and monitor your financial accounts for unauthorized transactions. Enable multi-factor authentication (MFA) on critical accounts to add an extra layer of security. Report the domain to your IT security team or the appropriate cybersecurity authority in your region. Avoid interacting with suspicious links or websites in the future, and verify the legitimacy of websites by checking for HTTPS, domain age, and user reviews before entering sensitive information. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-16 13:50:50 - Registrar: REGRU-RU - IP: 46.254.20.193 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["Hagezi"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/3146f648-ad0e-4e84-94d4-24ac47857316 - PhishDestroy: https://phishdestroy.io/domain/slon--1------at.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon--1------at.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon--1------at.ru/ Last updated: 2026-03-31