slon-4----cc[.]ru
“Slon2 cc: лучшее спортивное питание slon для ваших тренировок и достижений”
slon-4----cc.ru — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 6/94 (alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, Gridinsoft); PhishDestroy score 68/100. 注册商: REGRU-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, slon-4----cc.ru, is flagged as a fake login portal designed to harvest credentials from unsuspecting users. Analysis indicates the infrastructure was specifically engineered to mimic legitimate authentication pages, likely targeting users of financial services, email providers, or corporate login systems. The domain employs deceptive subdomain structures and URL obfuscation techniques to evade detection and increase the likelihood of successful phishing attempts. Given its elevated risk classification, this domain poses a significant threat to both individual and organizational security, particularly for those who may be tricked into entering sensitive information. Infrastructure analysis reveals concrete evidence supporting the malicious classification of slon-4----cc.ru. The domain resolves to the IP address 145.249.115.222 and was registered on March 28, 2026, through REGRU-RU, a registrar frequently associated with high-risk domains. VirusTotal reports that 6 out of 95 security vendors have flagged this domain as malicious, while it appears on one security blocklist and was previously identified in a threat intelligence pulse on AlienVault OTX. The domain has since been taken offline, but its brief operational window suggests a targeted campaign with limited exposure. Users who visited slon-4----cc.ru or entered credentials on any page hosted under this domain should take immediate action to mitigate potential risks. First, reset passwords for any accounts accessed during the suspected phishing attempt, prioritizing accounts linked to financial services, email, or corporate systems. Enable multi-factor authentication where available to add an additional layer of security. Monitor accounts for unauthorized activity, such as logins from unfamiliar locations or devices, and report any suspicious transactions to the relevant service provider. Additionally, scan local devices for malware, as phishing sites may distribute secondary payloads to maintain persistence or exfiltrate data. Organizations should review logs for connections to the domain or its associated IP address to assess potential compromise.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of slon-4----cc.ru · checked Jun 26, 2026
证据与外部报告
PD-20260328-396D3A Recipient: abuse@globconnex.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。