# slon3cc-o.ru — SUSPICIOUS > PhishDestroy flags slon3cc-o.ru as a live generic phishing domain impersonating a login page. Scan results show 0/95 VirusTotal detections—verify links before. ## Summary PhishDestroy identifies slon3cc-o.ru (seed: a449ac) as an active generic phishing domain designed to harvest login credentials. The domain does not currently impersonate a specific brand, indicating a broad credential-harvesting campaign. Infrastructure points to a crypto-drainer style kit, aligning with recent trends in opportunistic theft. slon3cc-o.ru was registered on March 08, 2026, through REGRU-RU and resolves to IP 205.185.113.136. The domain holds a valid Let’s Encrypt SSL certificate and currently shows zero detections on VirusTotal (0/95). Google Safe Browsing (GSB) has not yet blacklisted the domain, and no third-party blocklists flag it at this time. This domain is categorized as active and remains under investigation. Users are advised to avoid clicking links to slon3cc-o.ru and to verify any suspicious URLs using PhishDestroy. While no detections exist yet, the combination of fresh registration, live infrastructure, and generic phishing tooling presents a latent risk. Immediate containment is recommended until behavioral patterns and payloads are fully analyzed. Remaining risk is evaluated as elevated due to active status and unpatched detection gaps. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-08 01:22:33 - Registrar: REGRU-RU - IP: 205.185.113.136 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/e99ff20a-5027-452e-a278-3ec0e532687b - PhishDestroy: https://phishdestroy.io/domain/slon3cc-o.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon3cc-o.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon3cc-o.ru/ Last updated: 2026-03-28