# slon12to.net — SUSPICIOUS > Beware of slon12to.net, a medium-risk phishing site still active. Avoid sharing personal info and verify site safety before proceeding. ## Summary PhishDestroy identifies slon12to.net as a medium-risk generic phishing domain. Such threats aim to steal sensitive user data, posing risks to personal and financial security. The domain slon12to.net resolves to IP 172.67.158.167 and was created on March 13, 2026. It is registered through NiceNIC International Group Co., Limited and remains active. VirusTotal flags it with 3 out of 95 vendors, and it appears on one security blocklist. Users should avoid interacting with slon12to.net, especially refraining from entering any credentials or personal data. Always verify website legitimacy through trusted sources and use security tools to block suspicious domains. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 200) - Page title: slon12.to ## Domain Intelligence - Registered: 2026-03-13 03:07:02 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 172.67.158.167 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: blair.ns.cloudflare.com lochlan.ns.cloudflare.com - SSL Issuer: Let's Encrypt / E8 ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ce540-5bdf-762f-842c-96705d020203.png - PhishDestroy: https://phishdestroy.io/domain/slon12to.net/ - LLM endpoint: https://phishdestroy.io/domain/slon12to.net/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon12to.net/ Last updated: 2026-03-19