# slon3-cc-3.ru — SUSPICIOUS > slon3-cc-3.ru linked to a crypto drainer campaign. VirusTotal shows 0/95 detections. Avoid interacting with this domain immediately. ## Summary PhishDestroy identifies slon3-cc-3.ru as an active crypto drainer domain under investigation for credential theft and cryptocurrency siphoning. This domain was flagged due to its association with a generic phishing campaign targeting unsuspecting users, potentially harvesting sensitive login details or wallet access. This domain resolves to IP 185.212.128.10 and was registered through RU-CENTER-RU on March 23, 2026. The domain utilizes a Let's Encrypt SSL certificate, adding a false sense of legitimacy. Critically, VirusTotal currently shows 0/95 detections, indicating no immediate blocking by security vendors despite its malicious intent. Its recent creation date and low detection rate suggest it may evade traditional defenses, posing an elevated risk to visitors. If you have visited slon3-cc-3.ru, cease any interaction immediately and revoke any permissions granted to the site. Scan your device for malware and consider rotating cryptocurrency wallet credentials. Report the domain to your security team or relevant cybersecurity platforms to help block its spread. Exercise extreme caution with domains registered in the past few months, particularly those using Let's Encrypt certificates. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-23 14:46:23 - Registrar: RU-CENTER-RU - IP: 185.212.128.10 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/16d33874-2b9b-4100-a4f9-d2eb28550e40 - PhishDestroy: https://phishdestroy.io/domain/slon3-cc-3.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon3-cc-3.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon3-cc-3.ru/ Last updated: 2026-03-28