slon3----cc[.]vip
“Slon3 cc | Бесперебойные поставки строительных материалов по всей России | Slon3”
slon3----cc.vip — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 4/94 (Fortinet, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies slon3--cc.vip as an active domain engaged in generic phishing with potential crypto drainer functionality. The domain employs brand impersonation tactics to deceive users into connecting crypto wallets or disclosing credentials. No specific drainer kit fingerprint (e.g., Venom, PinkDrainer) has been confirmed in public sources, but the domain’s configuration aligns with common drainer deployment patterns involving fake NFT mints, wallet connection prompts, or token airdrop scams. The operational goal is asset exfiltration through transaction signing manipulation or direct wallet compromise.
This domain was flagged with the following technical indicators: VirusTotal detection score of 4/95 (undetected as of last scan), registered via NICENIC INTERNATIONAL GROUP CO., LIMITED, resolving to IP 199.217.99.9, secured with a Let’s Encrypt SSL certificate, and created on April 02, 2026. Google Safe Browsing (GSB) status remains unlisted, and no third-party blocklists currently include the domain. These indicators suggest a recently activated infrastructure with low detection coverage, increasing the risk of successful user compromise.
The campaign is currently active and under active monitoring by PhishDestroy. Users are advised to block the domain at network and DNS levels, avoid clicking any links, and verify all crypto-related transactions via official channels. While detection rates are low, the domain’s recent creation and clean reputation profile indicate elevated operational risk. Remaining risk includes continued phishing operations, potential pivot to new TLDs, or expansion into brand impersonation targeting high-value sectors such as DeFi or NFT communities. Immediate network-level blocking and user awareness are critical to prevent asset loss.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:19:30 UTC
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of slon3----cc.vip · checked Apr 4, 2026
Докази та зовнішні звіти
PD-20260404-965FA0 Recipient: abuse@nicenic.net, abuse@mmx.co Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога