slona4at[.]ru
“Slon4.at”
slona4at.ru — 内容不可用 (HTTP 502). 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 4/94 (alphaMountain.ai, G-Data, Gridinsoft, Sophos); PhishDestroy score 65/100. 注册商: REGRU-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain slona4at.ru indicates it was actively used for credential phishing targeting users of the Slon4.at platform. The domain, registered on March 28, 2026, through REGRU-RU, resolved to the IP address 91.236.116.22, hosted by w1n ltd in Sweden. Infrastructure analysis reveals the use of a Let's Encrypt SSL certificate (serial E7), a common choice for phishing sites due to its free and automated issuance. The page title, 'Slon4.at,' aligns with the reported scam type of credential phishing, suggesting an intent to mimic the legitimate Slon4.at service. Detection data shows the domain appeared on one security blocklist and was flagged by PhishDestroy.
VirusTotal results indicate that 4 out of 94 security vendors marked the domain as malicious, providing moderate but not universal confirmation of its threat status. AlienVault OTX recorded the domain in one threat intelligence pulse, further corroborating its association with malicious activity. As of July 22, 2026, the domain is offline, reducing immediate risk but leaving open the possibility of future reactivation or migration to new infrastructure. Defenders should treat this domain as part of a credential harvesting campaign targeting Slon4.at users.
While the exact content of the phishing page is not analyzed, the combination of page title, scam type, and detection data supports this classification. Organizations should monitor for related domains registered through REGRU-RU or hosted on the same IP range, as these may indicate follow-up campaigns. Blocking access to 91.236.116.22 and domains with similar naming patterns is recommended. If Slon4.at is a known service within your environment, alert users to the potential for credential theft and reinforce multi-factor authentication requirements.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of slona4at.ru · checked Mar 28, 2026
证据与外部报告
PD-20260328-77A1C3 Recipient: abuse@w1n.nl 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。