slon-3at[.]ru
“404 Not Found”
slon-3at.ru — Прикритий · доступний. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 93/100. Реєстратор: RU-CENTER-RU.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy has identified the active domain slon-3at.ru as a generic credential-harvesting page designed to mimic legitimate login portals and trick users into surrendering sensitive information such as usernames, passwords, and multi-factor authentication tokens. Based on current telemetry, the site does not appear to impersonate a specific brand but instead employs generic branding to broaden its potential victim pool. At this stage, forensic artifacts suggest the threat actor is leveraging a standard HTML-based drainer kit hosted on a server with minimal defensive coverage, allowing the campaign to remain under the radar while traffic is routed through a newly registered domain.
Technical indicators confirm the domain was registered through RU-CENTER-RU on February 21, 2026, and resolves to IP address 172.67.209.92. The site is secured with a Let's Encrypt SSL certificate, which may be used to lend false legitimacy to the page. Despite having no detections on VirusTotal (2/95 as of latest scan), the domain has not yet been flagged by Google Safe Browsing or widely added to public blocklists, indicating an early-stage campaign with limited exposure. The combination of a freshly registered domain, low detection rates, and standard infrastructure points to a rapidly evolving but currently low-signal threat that requires immediate monitoring.
The domain remains active and under active observation with a status labeled under_investigation. PhishDestroy recommends immediate network and endpoint blocking of slon-3at.ru and its resolving IP 172.67.209.92 due to the credible threat of credential theft. Users are advised to avoid interacting with any login prompts originating from this domain and to report suspicious activity to their security teams. While the current risk is classified as under_investigation, the absence of detection signatures and the use of trusted SSL infrastructure suggest the potential for rapid escalation if the campaign gains traction.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Перехресна перевірка даних про загрози · source references
Технології · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of slon-3at.ru · checked Mar 28, 2026
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога