# slon3cc-s.ru — SUSPICIOUS > PhishDestroy flags slon3cc-s.ru as a crypto-draining phishing site impersonating a major brand. 2 of 95 security vendors rate it malicious. ## Summary PhishDestroy identifies slon3cc-s.ru as an active crypto-draining phishing domain designed to trick users into connecting wallets and signing malicious transactions that silently drain funds. When accessed, the site presents a convincing fake login or wallet-connect prompt that, once authorized, permits the attacker to transfer cryptocurrency directly from the victim’s wallet without further confirmation. This is not a passive scam page; it actively requests blockchain permissions, making it a high-risk threat to anyone who interacts with it. This domain was flagged by PhishDestroy shortly after creation on March 8, 2026. It is registered through REGRU-RU and currently resolves to IP address 205.185.113.136. Notably, only 2 out of 95 VirusTotal security vendors have labeled it malicious to date. Despite its low initial detection rate, the site uses a valid Let’s Encrypt SSL certificate to appear legitimate, increasing the chance users will trust it. The combination of recent registration, minimal detections, and crypto-specific functionality places this domain at an elevated risk level. If you visited slon3cc-s.ru or entered any information, immediately revoke any blockchain wallet connections you authorized on the site. Use your wallet’s connection manager or blockchain explorer to inspect active permissions and revoke any unfamiliar or suspicious dApps. Never reuse wallets connected to this domain. For further verification, use PhishDestroy’s real-time lookup tool with the unique seed identifier ccae7c. Always verify URLs and ignore unsolicited links promising rewards or urgent actions, especially those involving cryptocurrency. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-08 01:22:33 - Registrar: REGRU-RU - IP: 205.185.113.136 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/efdf3dae-033b-49e8-9efd-ca8c32c8c4c0 - PhishDestroy: https://phishdestroy.io/domain/slon3cc-s.ru/ - LLM endpoint: https://phishdestroy.io/domain/slon3cc-s.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon3cc-s.ru/ Last updated: 2026-03-28