# slon-3-3at.ru — SUSPICIOUS > slon-3-3at.ru hosts a generic phishing crypto drainer with 0/95 VirusTotal detections. Avoid it entirely and scan all transactions. ## Summary PhishDestroy identifies slon-3-3at.ru as an active crypto-draining domain impersonating the Slon-3-3at brand. The site is currently under investigation yet remains reachable and unflagged by mainstream scanners, indicating it may still be in early deployment stages. This domain was flagged by 0 of 95 VirusTotal vendors, registered through FE-RU, resolves to 178.20.45.8, launched on March 24, 2026, and carries no blocklist entries or trust signals. With no detections and pristine reputation metrics, it poses a high deception risk for cryptocurrency users who may interact with it. Users should treat slon-3-3at.ru as hostile and avoid any transactional or login activity. Implement network-level blocks for 178.20.45.8, confirm all future transactions with on-chain verification, and share intelligence via threat-sharing platforms to accelerate detection by antivirus vendors. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-24 15:26:02 - Registrar: FE-RU - IP: 178.20.45.8 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/d65d65db-d529-427d-b4e5-7ad5a0e9a67b - PhishDestroy: https://phishdestroy.io/domain/slon-3-3at.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon-3-3at.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon-3-3at.ru/ Last updated: 2026-03-28