# slon2-cc.vip — SUSPICIOUS > Slon2-cc.vip is a recently identified phishing domain registered on April 1, 2026, resolving to 199.217.99.9. ## Summary PhishDestroy identifies slon2-cc.vip as an active phishing domain with a status marked as under investigation. The threat type is categorized as generic phishing, indicating the domain is likely deployed to deceive users into divulging sensitive information through spoofed login portals or fraudulent services. The risk level, while currently flagged as under investigation, remains a critical concern due to the domain's recent creation and the absence of detection on antivirus platforms. This domain was flagged by PhishDestroy after being registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 1, 2026. It resolves to the IP address 199.217.99.9 and utilizes a Let's Encrypt SSL certificate for perceived legitimacy. Notably, the domain remains undetected on 0 out of 95 VirusTotal scans, suggesting a low detection rate among security vendors. The lack of presence on reputable blocklists or threat intelligence feeds further highlights the domain's nascent and potentially evasive nature. To mitigate risks associated with slon2-cc.vip, users and organizations should immediately block the domain and its resolving IP (199.217.99.9) at the network level. Avoid interacting with any links or content originating from this domain, as it may lead to credential theft or malware deployment. Report the domain to relevant cybersecurity authorities, such as PhishDestroy or local CERT teams, to aid in its swift takedown. Additionally, verify the authenticity of any unsolicited communications referencing this domain, as phishing campaigns often exploit newly registered and unflagged infrastructure for deception. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-04-01 13:51:21 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 199.217.99.9 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/slon2-cc.vip - PhishDestroy: https://phishdestroy.io/domain/slon2-cc.vip/ - LLM endpoint: https://phishdestroy.io/domain/slon2-cc.vip/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon2-cc.vip/ Last updated: 2026-04-04