slon-3--3-at[.]ru
“Slon3.at â инÑеÑнеÑ-магазин авÑоÑÑкого ÑÐ°Ñ Ð¸ коÑе Ñ Ð´Ð¾ÑÑаЅ”
slon-3--3-at.ru — असत्यापित. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, SOCRadar); PhishDestroy score 81/100.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
slon-3--3-at.ru was first observed on March 28, 2026 and is currently serving HTTP content with a 200 response code. The site presents a title encoded in Cyrillic characters that translates to an internet‑magazine offering auto‑parts, indicating a likely lure aimed at Russian‑speaking consumers. The page is delivered over TLS 1.2 using a Let’s Encrypt certificate issued in the current year, confirming that the operator is able to obtain free certificates to lend legitimacy.
Technical reconnaissance shows the domain resolves to 168.100.8.206, an address hosted by a network provider in the Netherlands (BL Networks). The same IP has been associated with at least one other malicious indicator in recent threat‑intel feeds, and the host carries a Gridinsoft trust score of 0/100, reflecting a reputation of zero. VirusTotal scans have flagged the domain by 2 of 95 vendor engines, and AlienVault OTX includes the host in eight separate pulses, suggesting modest but growing awareness among analysts.
The combination of a language‑specific lure, a low‑cost TLS certificate, and the presence on the PhishDestroy blocklist points to a credential‑harvesting campaign that likely mimics legitimate e‑commerce or parts‑supplier sites. The limited number of VT detections may indicate that the phishing page is either newly deployed or uses evasion techniques that avoid triggering a larger set of scanners. No additional infrastructure such as command‑and‑control servers or malware drops has been observed, leaving the payload stage uncertain.
Defenders should add slon-3--3-at.ru and its resolved IP 168.100.8.206 to network and email filtering rules, and monitor for outbound connections to the host. Given the Russian‑language focus, organizations with Russian‑speaking staff or customers should prioritize user‑education messages about unexpected auto‑parts offers. Continuous re‑scanning of the domain is advised, as the content may evolve or additional sub‑domains could be activated.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of slon-3--3-at.ru · checked Mar 28, 2026
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।