slon-3--3-at[.]ru
“Slon3.at â инÑеÑнеÑ-магазин авÑоÑÑкого ÑÐ°Ñ Ð¸ коÑе Ñ Ð´Ð¾ÑÑаЅ”
slon-3--3-at.ru — 未验证. 证据摘要: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, SOCRadar); PhishDestroy score 81/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
slon-3--3-at.ru was first observed on March 28, 2026 and is currently serving HTTP content with a 200 response code. The site presents a title encoded in Cyrillic characters that translates to an internet‑magazine offering auto‑parts, indicating a likely lure aimed at Russian‑speaking consumers. The page is delivered over TLS 1.2 using a Let’s Encrypt certificate issued in the current year, confirming that the operator is able to obtain free certificates to lend legitimacy.
Technical reconnaissance shows the domain resolves to 168.100.8.206, an address hosted by a network provider in the Netherlands (BL Networks). The same IP has been associated with at least one other malicious indicator in recent threat‑intel feeds, and the host carries a Gridinsoft trust score of 0/100, reflecting a reputation of zero. VirusTotal scans have flagged the domain by 2 of 95 vendor engines, and AlienVault OTX includes the host in eight separate pulses, suggesting modest but growing awareness among analysts.
The combination of a language‑specific lure, a low‑cost TLS certificate, and the presence on the PhishDestroy blocklist points to a credential‑harvesting campaign that likely mimics legitimate e‑commerce or parts‑supplier sites. The limited number of VT detections may indicate that the phishing page is either newly deployed or uses evasion techniques that avoid triggering a larger set of scanners. No additional infrastructure such as command‑and‑control servers or malware drops has been observed, leaving the payload stage uncertain.
Defenders should add slon-3--3-at.ru and its resolved IP 168.100.8.206 to network and email filtering rules, and monitor for outbound connections to the host. Given the Russian‑language focus, organizations with Russian‑speaking staff or customers should prioritize user‑education messages about unexpected auto‑parts offers. Continuous re‑scanning of the domain is advised, as the content may evolve or additional sub‑domains could be activated.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of slon-3--3-at.ru · checked Mar 28, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。