MALICIOUS — CRITICAL
inv[.]finzon[.]io
18 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 18/91
- Blocklists
- 2 · MetaMask, SEAL
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
inv.finzon.io — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Argent; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 18/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrar: Hostinger.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Digest
inv.finzon.io is classified critical with an evidence score of 95/100. 18 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 12 Mar 2026 via HOSTINGER operations, UAB, hosted on 188.114.96.3 (Cloudflare, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)cerebras · 13.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain inv.finzon.io was registered on March 12, 2026 and resolves to the Cloudflare‑hosted address 188.114.96.3 (AS13335). The site serves HTTP 200 responses and presents the page title “Finzon”. Technical fingerprints show the use of Highcharts, Vue.js and HTTP/3, indicating a modern web stack. The SSL certificate is issued by SSL Corporation via the Cloudflare TLS Issuing ECC CA 3 chain. The domain is listed on three security blocklists and is actively blocked by PhishDestroy, MetaMask and SEAL. Gridinsoft assigns a trust score of 0 / 100, and VirusTotal records four detections out of ninety‑four scanners. The campaign targets the Argent brand and is classified as a crypto‑related scam, with a high risk rating. Infrastructure analysis confirms the domain remains active. Defenders should add inv.finzon.io to network‑level deny lists, enforce DNS filtering, and monitor for related subdomains or CNAME variations hosted on the same Cloudflare nameservers (merlin.ns.cloudflare.com, olga.ns.cloudflare.com). Continuous threat‑intel feeds should be consulted for any emerging indicators tied to the identified IP address or associated blocklist entries.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 4 identified
Progressive JavaScript framework for building user interfaces.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of inv.finzon.io · checked Mar 12, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.