# slon15at.net — SUSPICIOUS > Stay vigilant: slon15at.net is a reported phishing site. Avoid sharing personal info and do not interact with this domain to protect yourself. ## Summary PhishDestroy identifies slon15at.net as an active phishing domain designed to deceive users by mimicking legitimate sites. Classified under generic phishing threats, this domain aims to harvest sensitive information through fraudulent tactics. The site’s page title, "slon15.at," suggests an attempt to appear credible by resembling a legitimate web address. Technically, slon15at.net resolves to the IP address 104.21.54.34 and was registered recently on March 13, 2026, through NiceNIC International Group Co., Limited, a registrar that has been associated with various suspicious domains. The domain's infrastructure raises concerns as it appears on a known security blocklist, and VirusTotal flags it with 3 out of 95 security vendors indicating potential malicious activity. These indicators collectively reinforce its classification as a medium-risk phishing threat. Currently, slon15at.net remains active and should be avoided by internet users. PhishDestroy recommends exercising caution by not interacting with the domain or providing any personal or financial information. Security professionals and automated tools are advised to monitor the domain for any changes in infrastructure or threat activity. Users encountering this domain should report it to their security teams or use browser security features to block access. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 200) - Page title: slon15.at ## Domain Intelligence - Registered: 2026-03-13 03:07:02 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 104.21.54.34 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: blair.ns.cloudflare.com lochlan.ns.cloudflare.com - SSL Issuer: Let's Encrypt / E8 ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ce53d-32a0-7310-a3f8-1ed923f4ba3f.png - PhishDestroy: https://phishdestroy.io/domain/slon15at.net/ - LLM endpoint: https://phishdestroy.io/domain/slon15at.net/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon15at.net/ Last updated: 2026-03-19