# PhishDestroy threat dossier — slon3.net ================================================================ Fetched: 2026-05-30 03:08:06 UTC Canonical: https://phishdestroy.io/domain/slon3.net/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao, CRDF, CyRadar, Fortinet, G-Data, Gridinsoft, Lionic, Webroot URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.154.245 Registrar: Hosting Concepts B.V. d/b/a Registrar.eu Nameservers: ethan.ns.cloudflare.com, lily.ns.cloudflare.com Registered: 2026-02-16 Page title: SLON6.CC | SLON6.AT | slon3.at | slon3.cc HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-27 Status: INVALID chain Fingerprint: 6b03ea0e53c4da8ef0f556e1fc9332db3b9077d9fde77b8083c71e7a7e2f5e1a ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-26 05:30:10 UTC (by PhishDestroy tracker) First reported: 2026-05-25 10:09:26 UTC (abuse notice filed) Last verified: 2026-05-30 05:20:35 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e5e9a-480d-762d-82fd-74c40ad5b072/ URLQuery: https://urlquery.net/report/6455c58c-e600-4ec4-a5c0-388a86b15724 Wayback Machine: https://web.archive.org/web/*/slon3.net crt.sh CT logs: https://crt.sh/?q=%25.slon3.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=slon3.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/slon3.net URLhaus: https://urlhaus.abuse.ch/host/slon3.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-26 05:33:42 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] slon3.net presents an elevated risk as a confirmed fake cryptocurrency site phishing domain designed to deceive visitors into revealing sensitive wallet credentials or financial information. This domain mimics legitimate crypto platforms to exploit user trust, making it a high-concern threat to cryptocurrency investors and traders. PhishDestroy identifies slon3.net as a phishing vector with concrete indicators of compromise. VirusTotal reports show 12 out of 95 security vendors flagging this domain as malicious. Registered through Hosting Concepts B.V. d/b/a Registrar.eu, the domain was created on February 16, 2026 and resolves to IP address 172.67.154.245. It has been blocked by PhishDestroy and appears on one additional security blocklist. The domain holds an SSL certificate issued by Let's Encrypt, which does not guarantee legitimacy but enables encrypted communication for phishing payload delivery. To mitigate exposure to this fake crypto phishing site, avoid accessing slon3.net or any linked subdomains such as slon3.at, slon3.cc, slon6.at, or slon6.cc. If you have visited this site and entered any cryptocurrency wallet credentials or financial information, immediately revoke access to connected wallets, transfer funds to a secure offline wallet, and scan your devices for malware. Report the domain to your wallet provider and relevant cybersecurity authorities. Use browser extensions that block known phishing domains and enable multi-factor authentication on all crypto-related accounts. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260525-9858FB Favicon MD5: 8504beb6e34fc0e7dcd287828743e7b6 TLS cert SHA-256: 6b03ea0e53c4da8ef0f556e1fc9332db3b9077d9fde77b8083c71e7a7e2f5e1a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/slon3.net/ JSON API: https://api.destroy.tools/v1/check?domain=slon3.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 155,887 domains (34,624 alive under monitoring, 120,424 confirmed takedowns/dead). Site: https://phishdestroy.io