4slon5-cc[.]ru
“slon5.cc â РеÑÑавÑаÑÐ¸Ñ ÑовеÑÑÐºÐ¸Ñ ÑинÑезаÑоÑов в ÐоÑкве | Ð…”
4slon5-cc.ru — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); URLQuery 2 alerts; PhishDestroy score 76/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain 4slon5-cc.ru was registered on 12 May 2026 and is presently active. DNS resolution points to IP address 216.203.20.115, which is geolocated to the Netherlands and associated with the BL Networks hosting provider. The site presents a valid TLS certificate issued by Let’s Encrypt (E7), indicating that HTTPS traffic is encrypted. An HTTP request returns status code 200, confirming that the web server is responding. The page title retrieved from the site is "slon5.cc â РеÑÑавÑаÑÐ¸Ñ ÑовеÑÑÐºÐ¸Ñ ÑинÑезаÑоÑов ". No additional content analysis is available. Reputation scoring from Gridinsoft assigns a trust value of 0 out of 100, and the domain appears on a single security blocklist. VirusTotal analysis shows that 1 of 92 scanned security vendors flagged the domain, and AlienVault OTX lists it in one threat pulse. The domain is also listed as blocked by the PhishDestroy feed. The combination of recent registration, low trust score, presence on blocklists, and a single vendor detection suggests a high likelihood of malicious phishing activity, though the limited number of detections leaves some uncertainty about the full scope of the campaign. Defenders should block network traffic to 4slon5-cc.ru, monitor DNS queries for the domain, and consider adding the IP address 216.203.20.115 to deny lists. Continuous monitoring of threat feeds for additional indicators related to this infrastructure is recommended to capture any evolution of the campaign.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | 4slon5-cc.ru |
malicious | Sinkholed |
| DNS4EU | 4slon5-cc.ru |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。