Aller au rapport de sécurité
Checked 09/08/2026 Ref 6753ED04

MALICIOUS — CRITICAL

Analyse phishing et sécurité de slion4.cc

slion4[.]cc

Analysis indicates slion4.cc is an active high-risk domain associated with a generic phishing operation designed to deceive visitors into interacting with fraudulent web content.

88/100 evidence score · Critical
VirusTotal
6/91
Blocklists
No stored match
Disponibilité
Dernier actif connu · HTTP 200
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Ce domaine a été signalé comme malveillant
Moteurs de sécurité signalant une détection : 6. Faites preuve d’une extrême prudence – ne saisissez pas d’informations d’identification ou d’informations personnelles.
Jump to section
Résumé du rapport

slion4.cc — Dernier actif connu (HTTP 200). Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 88/100. Bureau d’enregistrement: NiceNIC.

L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.

Evidence Analysis

Ref 6753ED04

Analysis indicates slion4.cc is an active high-risk domain associated with a generic phishing operation designed to deceive visitors into interacting with fraudulent web content. The observed page title, "Captcha," suggests the infrastructure may be leveraging fake verification prompts to lower user suspicion, potentially preceding credential harvesting, malicious redirects, or additional staged social engineering workflows targeting sensitive user information.

Infrastructure analysis reveals the domain was created on June 08, 2026, indicating recently deployed attack infrastructure commonly associated with short-lifecycle malicious campaigns. Security telemetry shows detection by 8 out of 95 scanning engines, reflecting active but not yet universally recognized malicious classification. Registration records indicate the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Current monitoring confirms the domain remains active and has been identified on 1 independent security blocklist, supporting assessment of ongoing malicious operational status.

Users who accessed slion4.cc should immediately assume possible exposure to phishing infrastructure. Recommended response includes clearing browser session data, changing credentials entered during the visit, enabling multi-factor authentication on affected accounts, and monitoring for unauthorized login attempts. Systems used to access the domain should undergo endpoint security scanning to detect secondary payload delivery, browser persistence mechanisms, or credential theft artifacts potentially introduced during interaction with the malicious infrastructure.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
6 det.
OTX references
Certificat TLS
ZeroSSL GmbH / ZeroSSL ECC DV SSL CA 2
Âge
2 mo New
Statut observé
Dernier actif connu 200
PhishDestroy
DestroyList
Répertorié
Couverture des données12 recorded checks
VirusTotal 6 / 91 URLQuery pas vérifié PhishStats pas vérifié OTX 4 community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict indisponible Blocs DNS pas vérifié TLS valid certificate, 35d WHOIS 2 mo old Capture d'écran non capturé Chaîne de redirection non sondé
Renseignements sur la sécurité réseau Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Processus de réponse aux menaces Pipeline

Découverte
Checks
Reports
Disponibilité
9/11
Menace détectée
slion4.cc détectés et mis en file d'attente en vue d'une analyse complète
08/06/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
6/91 recorded on VirusTotal
05/08/2026
Google Safe Browsing
08/06/2026
OTX Community References
4 community publication references on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
09/06/2026
Registrar Context: NiceNIC
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Technical Analysis Recorded
Le rapport contient des résultats de technologie ou d’analyse médico-légale stockés.
09/08/2026
Cloudflare Radar Scan
Scanné avec le radar Cloudflare ; analyse du réseau terminée.
09/06/2026
Complaint Draft Available
Aucune soumission n'est enregistrée. Vous pouvez créer un brouillon, le réviser et le soumettre vous-même à l'autorité compétente.
DestroyList publié
08/06/2026
Monitoring Continues
Le domaine reste accessible ou restreint en accès ; des contrôles futurs pourraient mettre à jour cette observation.

Statut de la liste de blocage publique

Informations sur les domaines

Domaine
Serveur / ASN AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP
Réputation de l’IP abuse score 0/100 0 reports checked 01/08/2026
Adresse IP 185.236.20.203 NL
LocalisationNL Amsterdam, NL
RéseauAS215540 · Global Connectivity Solutions LLP
EnregistrementCréé 08/06/2026 (62d · New)
Elapsed Since First Report 44h
Ce que nous comptons Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Dernier actif connu.
Ce que contient chaque rapport Les enregistrements de rapports sortants stockés peuvent faire référence à des preuves disponibles à ce moment-là, telles que les verdicts des fournisseurs, les données d'enregistrement, les détails d'hébergement, les classifications ou les captures d'écran. Cette page ne déduit pas la charge utile exacte livrée, la réception, l'accusé de réception ou l'action d'un destinataire.
Statut HTTP200
Détails techniquesDNS, SAN SSL, horodatages
Première détection08/06/2026
Submitted URLhttp://slion4.cc/
Serveurs de nomsluciana.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 15/06/2026scanned 02/07/2026

Latest Classified Outcome 2026-08-09 02:45:57 UTC

Primary outcome Live content reason: Ordinary HTTP content served 90% confidence
Attribution source: Current Http Probe
Evidence layers Availability: Content serving Content: Content served at root DNS: Resolved Registration: Active
Latest HTTP observation Live content Ordinary HTTP content served 90% 2026-08-09 02:45:57 UTC
RDAP registration Actif NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibited expires 2027-05-14 06:53:23 UTC checked 2026-08-05 19:11:41 UTC
Observed timeline last reachable: 2026-08-09 02:45:57 UTC last content: 2026-08-09 02:45:57 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Technologies · 2 identified
HSTS
Sécurité

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org Confiance à 100 %
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org Confiance à 100 %
Detected via Cloudflare Radar · Wappalyzer engine
Signaler ce domaine Envoyez des éléments de preuve et contribuez à protéger les autres

Analyse VirusTotal

6 / Les fournisseurs de sécurité 91 ont signalé ce domaine
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
CRDF
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
SOCRadar
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.

Europol
Trouvez le canal de signalement officiel pour votre pays de l'UE
National police directory
Méfiez-vous des escrocs qui prétendent vous aider à récupérer vos biens ! Les criminels peuvent recontacter leurs victimes tout en se faisant passer pour des enquêteurs, des avocats ou des agents de recouvrement. Ne payez pas de frais initiaux et ne partagez pas vos informations d'identification. En savoir plus sur la fraude liée aux aides à la reprise →

Signalez-le à vos autorités locales

Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.

Annuaire de 97 pays
Brouillon assisté par l'IA : les détails de l'incident sont traités par le fournisseur d'IA Examinez-le et soumettez-le vous-même
Intégrer ce rapportRead-only HTML widget
HTML · IFRAME

Intégrer ce rapport

Partagez ces informations sur les menaces sur votre site web ou votre blog

embed.html
<iframe
  src="https://phishdestroy.io/fr/embed/domain/slion4.cc"
  title="PhishDestroy threat report for slion4.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>