slon-3--3-at[.]ru
“Slon3.at â инÑеÑнеÑ-магазин авÑоÑÑкого ÑÐ°Ñ Ð¸ коÑе Ñ Ð´Ð¾ÑÑаЅ”
slon-3--3-at.ru — Non vérifié. Résumé des preuves: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, SOCRadar); PhishDestroy score 81/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
slon-3--3-at.ru was first observed on March 28, 2026 and is currently serving HTTP content with a 200 response code. The site presents a title encoded in Cyrillic characters that translates to an internet‑magazine offering auto‑parts, indicating a likely lure aimed at Russian‑speaking consumers. The page is delivered over TLS 1.2 using a Let’s Encrypt certificate issued in the current year, confirming that the operator is able to obtain free certificates to lend legitimacy.
Technical reconnaissance shows the domain resolves to 168.100.8.206, an address hosted by a network provider in the Netherlands (BL Networks). The same IP has been associated with at least one other malicious indicator in recent threat‑intel feeds, and the host carries a Gridinsoft trust score of 0/100, reflecting a reputation of zero. VirusTotal scans have flagged the domain by 2 of 95 vendor engines, and AlienVault OTX includes the host in eight separate pulses, suggesting modest but growing awareness among analysts.
The combination of a language‑specific lure, a low‑cost TLS certificate, and the presence on the PhishDestroy blocklist points to a credential‑harvesting campaign that likely mimics legitimate e‑commerce or parts‑supplier sites. The limited number of VT detections may indicate that the phishing page is either newly deployed or uses evasion techniques that avoid triggering a larger set of scanners. No additional infrastructure such as command‑and‑control servers or malware drops has been observed, leaving the payload stage uncertain.
Defenders should add slon-3--3-at.ru and its resolved IP 168.100.8.206 to network and email filtering rules, and monitor for outbound connections to the host. Given the Russian‑language focus, organizations with Russian‑speaking staff or customers should prioritize user‑education messages about unexpected auto‑parts offers. Continuous re‑scanning of the domain is advised, as the content may evolve or additional sub‑domains could be activated.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of slon-3--3-at.ru · checked Mar 28, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif