Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net, compliance@icann.org.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
slon-2[.]to
“slon2.to”
slon-2.to — Último ativo conhecido (HTTP 200). Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 4/91 (alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 72/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
slon-2.to has been identified as an active tech-support scam domain designed to mimic legitimate support pages and trick users into dialing fraudulent hotlines. Once loaded, the page displays fabricated system alerts claiming malware infections or licensing issues, urging immediate phone contact. Attackers then coerce victims into providing remote-desktop access or divulging payment card details, resulting in credential theft and financial loss. This domain was flagged by PhishDestroy’s pipeline using seed 79c3df after VirusTotal returned 0 detections out of 95 scanning engines, indicating no current signature coverage. slon-2.to was registered on February 22, 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IP 172.67.202.27 behind a Let’s Encrypt certificate. The combination of a fresh registration, low detection rate, and hosting provider anonymity places users at heightened risk. Historical telemetry shows zero prior listings on major blocklists, underscoring its novelty and evasiveness. If you visited slon-2.to, close the browser immediately and avoid any prompts for phone calls or downloads. Scan your device with an updated antivirus tool to check for unauthorized remote-access software. Rotate passwords saved in browsers and enable multi-factor authentication on critical accounts. Report the domain to your IT security team and submit a screenshot to PhishDestroy using seed 79c3df to aid further takedown efforts.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Latest Classified Outcome 2026-08-15 02:47:18 UTC
Tecnologias · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of slon-2.to · checked Mar 28, 2026
Evidências e relatórios externos
PD-20260328-5AEECC Recipient: abuse@nicenic.net, compliance@icann.org Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo