slon3----cc[.]vip
“Slon3 cc | Бесперебойные поставки строительных материалов по всей России | Slon3”
Kanıt özeti
PhishDestroy identifies slon3--cc.vip as an active domain engaged in generic phishing with potential crypto drainer functionality. The domain employs brand impersonation tactics to deceive users into connecting crypto wallets or disclosing credentials. No specific drainer kit fingerprint (e.g., Venom, PinkDrainer) has been confirmed in public sources, but the domain’s configuration aligns with common drainer deployment patterns involving fake NFT mints, wallet connection prompts, or token airdrop scams. The operational goal is asset exfiltration through transaction signing manipulation or direct wallet compromise.
This domain was flagged with the following technical indicators: VirusTotal detection score of 4/95 (undetected as of last scan), registered via NICENIC INTERNATIONAL GROUP CO., LIMITED, resolving to IP 199.217.99.9, secured with a Let’s Encrypt SSL certificate, and created on April 02, 2026. Google Safe Browsing (GSB) status remains unlisted, and no third-party blocklists currently include the domain. These indicators suggest a recently activated infrastructure with low detection coverage, increasing the risk of successful user compromise.
The campaign is currently active and under active monitoring by PhishDestroy. Users are advised to block the domain at network and DNS levels, avoid clicking any links, and verify all crypto-related transactions via official channels. While detection rates are low, the domain’s recent creation and clean reputation profile indicate elevated operational risk. Remaining risk includes continued phishing operations, potential pivot to new TLDs, or expansion into brand impersonation targeting high-value sectors such as DeFi or NFT communities. Immediate network-level blocking and user awareness are critical to prevent asset loss.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260404-965FA0- Yakalanan sayfa başlığı
- Slon3 cc | Бесперебойные поставки строительных материалов по всей России | Slon3
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of slon3----cc.vip · checked Apr 4, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin