MALICIOUS — CRITICAL
Análisis de phishing y seguridad de slion4.cc
slion4[.]
Analysis indicates slion4.cc is an active high-risk domain associated with a generic phishing operation designed to deceive visitors into interacting with fraudulent web content.
- VirusTotal
- 6/91
- Blocklists
- No stored match
- Disponibilidad
- Último activo conocido · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
slion4.cc — Último activo conocido (HTTP 200). Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 88/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
Analysis indicates slion4.cc is an active high-risk domain associated with a generic phishing operation designed to deceive visitors into interacting with fraudulent web content. The observed page title, "Captcha," suggests the infrastructure may be leveraging fake verification prompts to lower user suspicion, potentially preceding credential harvesting, malicious redirects, or additional staged social engineering workflows targeting sensitive user information.
Infrastructure analysis reveals the domain was created on June 08, 2026, indicating recently deployed attack infrastructure commonly associated with short-lifecycle malicious campaigns. Security telemetry shows detection by 8 out of 95 scanning engines, reflecting active but not yet universally recognized malicious classification. Registration records indicate the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Current monitoring confirms the domain remains active and has been identified on 1 independent security blocklist, supporting assessment of ongoing malicious operational status.
Users who accessed slion4.cc should immediately assume possible exposure to phishing infrastructure. Recommended response includes clearing browser session data, changing credentials entered during the visit, enabling multi-factor authentication on affected accounts, and monitoring for unauthorized login attempts. Systems used to access the domain should undergo endpoint security scanning to detect secondary payload delivery, browser persistence mechanisms, or credential theft artifacts potentially introduced during interaction with the malicious infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Latest Classified Outcome 2026-08-09 02:45:57 UTC
Tecnologías · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.