slon3-----cc[.]vip
“Slon3 cc | Бесперебойное снабжение строительных объектов по РФ | Slon3”
slon3-----cc.vip — Прикритий · доступний (HTTP 502). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 3/94 (Fortinet, Gridinsoft); Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 71/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies slon3-----cc.vip as an active Slack credential phishing domain under investigation. This domain is currently distributing a fake Slack login page designed to harvest corporate credentials. Users arriving at this site via phishing emails, malicious ads, or typosquatting links are prompted to enter their Slack credentials, which are then transmitted to the attacker’s server. The site is operational and poses a significant risk to organizations using Slack, especially those with remote or hybrid workflows that rely heavily on the platform for communication.
This domain was flagged by 3 of 95 VirusTotal security vendors at time of analysis, indicating that while undetected by most AV engines, its malicious nature has been independently verified through behavioral and infrastructure analysis. slon3-----cc.vip resolves to IP address 64.7.198.31, is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, and was created on April 18, 2026. It uses a valid SSL certificate issued by Let’s Encrypt, which increases its deceptive appearance and enables encrypted data exfiltration of stolen credentials. The domain is not yet listed on major blocklists, reflecting its recent emergence and the lag in threat intelligence feeds.
The current status of slon3-----cc.vip is active and its infrastructure is stable. Given the absence of AV detections and blocklist inclusion, organizations are strongly advised to implement domain-based monitoring and block this domain at network firewalls and DNS resolvers immediately. Users should avoid interacting with this domain and be alert for phishing emails impersonating Slack. If credentials have been entered, users must rotate passwords immediately and enable multi-factor authentication (MFA). Consider reporting incidents to Slack’s Trust & Safety team using the phishing submission form at slack.com/help/requests. Proactive threat hunting based on IP 64.7.198.31 and SSL fingerprint is recommended to identify lateral compromise or credential reuse across systems.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:19:30 UTC
Технології · 4 identified
C is a general-purpose, procedural computer programming language supporting structured programming, lexical variable scope, and recursion, with a static type system.
www.open-std.org 100% впевненостіPerl is a family of two high-level, general-purpose, interpreted, dynamic programming languages.
perl.org 100% впевненостіAngie is a drop-in replacement for the Nginx web server aiming to extend the functionality of the original version.
angie.software 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of slon3-----cc.vip · checked Apr 21, 2026
Докази та зовнішні звіти
PD-20260421-1C6E68 Recipient: abuse@nicenic.net, abuse@mmx.co Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога