slon-3at[.]ru
“404 Not Found”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
content_divergence- Gizleme puanı
- 4/6
Kanıt özeti
PhishDestroy has identified the active domain slon-3at.ru as a generic credential-harvesting page designed to mimic legitimate login portals and trick users into surrendering sensitive information such as usernames, passwords, and multi-factor authentication tokens. Based on current telemetry, the site does not appear to impersonate a specific brand but instead employs generic branding to broaden its potential victim pool. At this stage, forensic artifacts suggest the threat actor is leveraging a standard HTML-based drainer kit hosted on a server with minimal defensive coverage, allowing the campaign to remain under the radar while traffic is routed through a newly registered domain.
Technical indicators confirm the domain was registered through RU-CENTER-RU on February 21, 2026, and resolves to IP address 172.67.209.92. The site is secured with a Let's Encrypt SSL certificate, which may be used to lend false legitimacy to the page. Despite having no detections on VirusTotal (2/95 as of latest scan), the domain has not yet been flagged by Google Safe Browsing or widely added to public blocklists, indicating an early-stage campaign with limited exposure. The combination of a freshly registered domain, low detection rates, and standard infrastructure points to a rapidly evolving but currently low-signal threat that requires immediate monitoring.
The domain remains active and under active observation with a status labeled under_investigation. PhishDestroy recommends immediate network and endpoint blocking of slon-3at.ru and its resolving IP 172.67.209.92 due to the credible threat of credential theft. Users are advised to avoid interacting with any login prompts originating from this domain and to report suspicious activity to their security teams. While the current risk is classified as under_investigation, the absence of detection signatures and the use of trusted SSL infrastructure suggest the potential for rapid escalation if the campaign gains traction.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of slon-3at.ru · checked Mar 28, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin