slon3at-3at[.]ru
“Slon3 at метод автоматизированного контроля качества https процессов”
slon3at-3at.ru — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: ["telegram"]; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 5/94 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Kayıt kuruluşu: REGRU-RU.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, slon3at-3at.ru, is flagged as a generic phishing threat designed to mimic automated HTTPS process control verification systems. The page title, "Slon3 at метод автоматизированного контроля качества https процессов," suggests an attempt to deceive users into believing the site is a legitimate quality control interface for secure web processes. Such phishing domains often target enterprise environments, aiming to harvest credentials or distribute malicious payloads under the guise of system validation tools. The domain’s focus on HTTPS processes indicates a potential risk to organizations relying on automated security monitoring or compliance workflows. Analysis indicates the domain was registered on March 28, 2026, through REGRU-RU, a registrar frequently associated with malicious infrastructure. It resolves to the IP address 205.185.113.136 and is currently offline. VirusTotal reports 5 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. The server runs Nginx, a common web server technology that may be exploited to host phishing content or redirect victims to secondary malicious endpoints. The domain’s creation date, set in the future, further suggests an attempt to evade detection by appearing as a newly established, unmonitored resource. Users who visited slon3at-3at.ru should immediately revoke any credentials entered on the site, as they may have been compromised. Network administrators should block the domain and its resolving IP (205.185.113.136) at the firewall or DNS level to prevent further access. Endpoints that interacted with the domain should be scanned for malware or unauthorized modifications, particularly those related to HTTPS process monitoring or automation tools. If the domain was accessed in a corporate environment, incident response protocols should be initiated to assess potential data exposure or lateral movement risks. Future monitoring for similar domains using the "slon3at" naming convention or targeting automated process control systems is recommended.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of slon3at-3at.ru · checked Jun 26, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin