MALICIOUS — HIGH
slon7l[.]cc
PhishDestroy identifies slon7l.cc as an active crypto-drainer site designed to steal cryptocurrency from unwary visitors.
- VirusTotal
- 3/92
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
slon7l.cc — Ultimo attivo conosciuto (HTTP 302). Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 3/92 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 69/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies slon7l.cc as an active crypto-drainer site designed to steal cryptocurrency from unwary visitors. When loaded, the page loads obfuscated JavaScript that silently connects to a drainer wallet and siphons tokens from connected wallets the moment users approve any transaction. The domain attempts to appear legitimate by using a Let's Encrypt SSL certificate and a short, random string name meant to bypass simple blocklists. This domain was flagged by PhishDestroy on April 10, 2026, the same day it was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. VirusTotal analysis shows only 2 out of 95 participating security engines currently detect the threat, leaving most users exposed if they rely on generic antivirus feeds. The combination of a fresh registration, low detection rate, and active drainer payload places this domain in the elevated-risk category and warrants immediate caution. If you visited slon7l.cc or clicked any link on the page, disconnect your wallet immediately and revoke any unauthorized approvals using tools like revoke.cash or your wallet’s built-in allowance manager. Do not interact with any further prompts or approve additional transactions. Report the domain to PhishDestroy for takedown and scan your device with updated antivirus software. Treat all wallet connections and transaction approvals with extreme skepticism until you can verify the destination using PhishDestroy’s real-time link checker.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Latest Classified Outcome 2026-08-09 02:11:51 UTC
Tecnologie · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of slon7l.cc · checked May 11, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260510-1505E1 Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.