slon-3at[.]ru
“404 Not Found”
slon-3at.ru — ढका हुआ · पहुंच योग्य. घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 93/100. रजिस्ट्रार: RU-CENTER-RU.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
PhishDestroy has identified the active domain slon-3at.ru as a generic credential-harvesting page designed to mimic legitimate login portals and trick users into surrendering sensitive information such as usernames, passwords, and multi-factor authentication tokens. Based on current telemetry, the site does not appear to impersonate a specific brand but instead employs generic branding to broaden its potential victim pool. At this stage, forensic artifacts suggest the threat actor is leveraging a standard HTML-based drainer kit hosted on a server with minimal defensive coverage, allowing the campaign to remain under the radar while traffic is routed through a newly registered domain.
Technical indicators confirm the domain was registered through RU-CENTER-RU on February 21, 2026, and resolves to IP address 172.67.209.92. The site is secured with a Let's Encrypt SSL certificate, which may be used to lend false legitimacy to the page. Despite having no detections on VirusTotal (2/95 as of latest scan), the domain has not yet been flagged by Google Safe Browsing or widely added to public blocklists, indicating an early-stage campaign with limited exposure. The combination of a freshly registered domain, low detection rates, and standard infrastructure points to a rapidly evolving but currently low-signal threat that requires immediate monitoring.
The domain remains active and under active observation with a status labeled under_investigation. PhishDestroy recommends immediate network and endpoint blocking of slon-3at.ru and its resolving IP 172.67.209.92 due to the credible threat of credential theft. Users are advised to avoid interacting with any login prompts originating from this domain and to report suspicious activity to their security teams. While the current risk is classified as under_investigation, the absence of detection signatures and the use of trusted SSL infrastructure suggest the potential for rapid escalation if the campaign gains traction.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
थ्रेट इंटेलिजेंस क्रॉस-रेफ़रेंस · source references
तकनीकें · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of slon-3at.ru · checked Mar 28, 2026
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।