# slon3cc-n.ru — SUSPICIOUS > Domain slon3cc-n.ru is a crypto drainer scam with 0/95 VirusTotal detections. Avoid this active phishing site now. ## Summary PhishDestroy identifies the domain slon3cc-n.ru as an active crypto drainer scam designed to steal cryptocurrency assets from unsuspecting victims. This domain resolves to IP address 205.185.113.136 and operates with a Let’s Encrypt SSL certificate, lending it an air of legitimacy. The domain was registered on March 08, 2026, through REGRU-RU, a registrar known for hosting both legitimate and malicious domains. Currently, VirusTotal shows zero detections out of 95 security engines, indicating that its malicious nature has not yet been widely recognized. The lack of current blocklist entries further enables its short-term persistence, but ongoing threat intelligence efforts are rapidly identifying and mitigating such threats. This crypto drainer specifically targets cryptocurrency users by impersonating legitimate platforms or services, tricking users into connecting their wallets or entering credentials. Technical indicators, including the domain’s recent creation and low detection rate, suggest a newly launched operation with high potential for victimization. The use of a legitimate-looking SSL certificate adds to its deceptive appeal, increasing the likelihood of successful credential theft or fund siphoning. While the domain currently remains under investigation, its active status and minimal detection footprint make it a significant threat to crypto holders who may interact with it under false pretenses. Users who have visited slon3cc-n.ru or entered any information on the site should immediately disconnect their wallets, revoke any connected permissions, and transfer remaining funds to a secure, offline wallet. Run a full antivirus scan, clear browser cache and cookies, and monitor financial accounts for unauthorized activity. Report the domain to your antivirus provider and relevant cybersecurity authorities to aid in its takedown. Avoid interacting with this domain or any associated links to prevent further compromise. Stay vigilant—crypto drainers like this one evolve quickly, and early detection is key to asset protection. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-08 01:22:35 - Registrar: REGRU-RU - IP: 205.185.113.136 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/7492d28e-0c2d-4ff8-8dd2-8c3adfc250ae - PhishDestroy: https://phishdestroy.io/domain/slon3cc-n.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon3cc-n.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon3cc-n.ru/ Last updated: 2026-03-28