# slon-2-aat.ru — SUSPICIOUS > slon-2-aat.ru is a fake Aat payment portal flagged by 1 of 95 VirusTotal vendors. Check the full report. ## Summary slon-2-aat.ru is identified as a phishing domain impersonating Aat payment services, currently active and posing an elevated risk to users. This domain mimics legitimate financial portals to deceive visitors into disclosing sensitive payment credentials or personal information. The threat remains unresolved and continues to operate without takedown interventions. This domain was flagged by 1 of 95 VirusTotal security vendors, indicating low but present detection coverage. It is registered through REGRU-RU, resolves to IP 188.114.97.3, and was created on March 20, 2026. No known blocklist entries or trust scores are available at this time, suggesting a newly emerged threat with minimal historical scrutiny. The domain remains active and unblocked. Users are advised to avoid interaction and report the domain to their security teams or local CERT. Organizations should block the domain and IP at the network perimeter. Continuous monitoring is recommended due to the evolving nature of phishing campaigns and the potential for rapid escalation in threat sophistication. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-20 15:02:47 - Registrar: REGRU-RU - IP: 188.114.97.3 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/116a011b-2d1f-45f0-8e4a-4eaeb79e691b - PhishDestroy: https://phishdestroy.io/domain/slon-2-aat.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon-2-aat.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon-2-aat.ru/ Last updated: 2026-03-28