# slon5.at — SUSPICIOUS > PhishDestroy identifies slon5.at as a fake login portal scam. Resolving to 64.190.63.222, it has 0/95 VirusTotal detections. Check the full report. ## Summary slon5.at has been flagged as an active fake login portal scam, posing a significant risk to unsuspecting users. This domain mimics legitimate login pages to harvest credentials, typically targeting victims through deceptive emails or messages. The threat level remains under investigation, but preliminary findings confirm malicious intent. Users are strongly advised to avoid interacting with this domain until further analysis is complete. This domain was flagged by PhishDestroy with the following indicators: VirusTotal shows 0/95 security vendor detections as of the latest scan, indicating low immediate detection but not ruling out evasion techniques. The domain is registered through Key-Systems GmbH (nic.at registrar ID 404) and resolves to IP address 64.190.63.222, which is associated with suspicious hosting infrastructure. The SSL certificate, issued by DigiCert Inc, adds a false sense of legitimacy, further deceiving potential victims. No blocklist entries or trust scores are currently available, leaving users with no prior warnings. To mitigate risks, users should immediately block slon5.at at the network and DNS levels. Avoid clicking on any links or entering credentials on this domain. Organizations should update firewall rules to block traffic to 64.190.63.222 and inspect outbound connections for suspicious activity. If credentials were entered, reset passwords immediately and enable multi-factor authentication where possible. Report this domain to your security team or through PhishDestroy’s portal to aid in ongoing investigations. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Key-Systems GmbH ( https://nic.at/registrar/404 ) - IP: 64.190.63.222 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/4209e06f-c519-4962-b005-462d9b2ccfab - PhishDestroy: https://phishdestroy.io/domain/slon5.at/ - LLM endpoint: https://phishdestroy.io/domain/slon5.at/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/slon5.at/ Last updated: 2026-03-28