slon2----at---at[.]ru
“Slon2.at â инÑеÑнеÑ-магазин наÑÑолÑнÑÑ Ð¸Ð³Ñ Ð¸ головоломок …”
slon2----at---at.ru — Non vérifié. Résumé des preuves: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, SOCRadar); PhishDestroy score 76/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain slon2----at---at.ru indicates active credential phishing infrastructure targeting Russian-speaking users. The domain, registered on March 28, 2026, resolves to IP address 168.100.8.206, hosted in the Netherlands under ASN associated with BL Networks. The page returns an HTTP 200 status and presents a localized storefront in Russian, titled 'Slon2.at — интернет-магазин настольных игр и головоломок с доставкой по России,' designed to mimic a legitimate online retailer. The use of a Let's Encrypt SSL certificate (serial E7) provides HTTPS encryption, increasing the appearance of legitimacy to potential victims. Current detection metrics show limited but clear malicious classification. Two out of 95 security vendors on VirusTotal flag the domain as malicious, and it appears on one security blocklist. Additionally, the domain is referenced in one AlienVault OTX threat intelligence pulse, suggesting prior observation in phishing campaigns. The domain's Gridinsoft trust score of 0/100 further supports its classification as high-risk. While the exact phishing kit or brand impersonation is not confirmed, the combination of recent registration, low detection but consistent blocking, and localized content indicates a targeted campaign. Defenders should treat this domain as an active threat. The infrastructure remains operational as of July 12, 2026, and continues to serve content. Network-level blocking is recommended, particularly for organizations with Russian-speaking users or those in the retail or gaming sectors. Monitoring for connections to 168.100.8.206 and correlating with endpoint logs for credential access or unusual checkout behavior may help identify compromised users. Given the domain's presence on only one blocklist, broader detection coverage may be limited, so proactive hunting using the domain, IP, and SSL certificate fingerprint is advised.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of slon2----at---at.ru · checked Mar 28, 2026
Analyse de la configuration du site
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif