slon-2---------at[.]ru
“Slon2 AT â инÑеÑнеÑ-магазин кÑаÑÑового Ñоколада bean-to-bar Ñ Ð…”
slon-2---------at.ru — 未验证. 证据摘要: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, SOCRadar); PhishDestroy score 76/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of slon-2---------at.ru shows a newly registered domain (creation date 28 March 2026) that is actively serving HTTP content (status 200) over a valid Let's Encrypt certificate (E8). The domain resolves to IP 168.100.8.206, hosted in the Netherlands under the BL Networks provider. The page title returned by the server is a garbled Russian string referencing an internet‑magazine for bean‑to‑bar chocolate, indicating that the site may be attempting to lure Russian‑speaking users with a product‑related lure, but the exact phishing payload has not been captured. The site is listed on one public blocklist, is blocked by the PhishDestroy feed, and appears in a single AlienVault OTX pulse. Reputation services rate the site at 0/100 on Gridinsoft, and two of ninety‑four VirusTotal scanners have flagged it as malicious. The risk rating is high and the domain remains active. Defenders should add the IP address 168.100.8.206 and the fully qualified domain name to outbound and inbound filtering rules, monitor DNS queries for the domain, and ensure that any email or web traffic that references the observed title string is inspected for credential‑harvesting behavior. Continuous re‑evaluation is advised as additional intelligence becomes available.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of slon-2---------at.ru · checked Mar 28, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。