# slon3cc-3.ru — SUSPICIOUS > slon3cc-3.ru is a credential harvesting phishing site hosted on 205.185.113.136. Users should avoid this domain entirely and report it immediately. ## Summary PhishDestroy identifies slon3cc-3.ru as an active credential harvesting phishing site targeting unsuspecting users. The domain is currently under investigation but remains operational, posing an immediate threat to anyone who accesses it. This site mimics legitimate login portals to steal credentials, banking details, or personal data under false pretenses. This domain was flagged by 0 of 95 VirusTotal vendors despite hosting malicious content. It was registered through REGRU-RU on March 13, 2026, resolving to IP address 205.185.113.136. The site utilizes a Let's Encrypt SSL certificate, which may falsely imply legitimacy to users. At the time of analysis, the domain is not listed on major blocklists, and trust scores remain critically low due to its recent creation and lack of established reputation. The current status of slon3cc-3.ru is active and dangerous. Users are strongly advised to avoid this domain entirely, report it to their security teams or browser vendors, and warn others. Organizations should update firewall rules and DNS blocklists to prevent access. If credentials were accidentally entered, users must change passwords immediately and monitor accounts for unauthorized activity. Security teams should investigate any logs for connections to this IP or domain, as it may indicate compromised systems within their network. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-13 01:15:11 - Registrar: REGRU-RU - IP: 205.185.113.136 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/67644213-80c3-4b3a-b027-4239ae16df1a - PhishDestroy: https://phishdestroy.io/domain/slon3cc-3.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon3cc-3.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon3cc-3.ru/ Last updated: 2026-03-28