MALICIOUS — CRITICAL
finovexus[.]com
PhishDestroy identifies finovexus.com as an active credential theft phishing site designed to harvest login credentials under the guise of a legitimate financial service.
- VirusTotal
- 6/91
- Blocklists
- No stored match
- Ketersediaan
- Terakhir diketahui aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@whiteprivacy.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
finovexus.com — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 6/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Netcraft); URLQuery 3 alerts; Spamhaus DBL_SPAM; PhishDestroy score 92/100. Registrar: Hosting Concepts.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
PhishDestroy identifies finovexus.com as an active credential theft phishing site designed to harvest login credentials under the guise of a legitimate financial service. The domain mimics professional branding to trick users into entering sensitive information, likely targeting crypto wallets, banking portals, or investment platforms. Security researchers have observed this pattern in recent campaigns where threat actors rapidly register domains to evade takedown efforts. This domain was flagged by PhishDestroy after VirusTotal scanners confirmed elevated malicious activity—only 1 out of 95 security vendors detected the threat as of seed 9c701c. Technical indicators include a newly registered domain (March 27, 2026), hosting on IP 163.61.188.9, and registration through Hosting Concepts B.V. d/b/a Registrar.eu. The presence of a Let’s Encrypt SSL certificate suggests an attempt to appear legitimate, while the low detection rate highlights evasion tactics. Users who visited finovexus.com should immediately change passwords for any accounts exposed during the visit and enable multi-factor authentication where available. Scan devices for malware using reputable antivirus tools and monitor financial accounts for unauthorized transactions. Report the domain to your organization’s security team or file a complaint with the FBI IC3 if personal data was entered. Avoid reaccessing the site and warn others in your network to prevent further compromise.
Cakupan data14 recorded checks
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/14a/common.js |
audit | Hunting_JS_WebAssembly |
| Private YARA rules | www.youtube.com/s/player/2d01abf7/player_embed_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | finovexus.com |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 12 identified
Chart.js is an open-source JavaScript library that allows you to draw different types of charts by using the HTML5 canvas element.
www.chartjs.org 75% confidenceYouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.com Keyakinan 100%Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com Keyakinan 100%Smartsupp is a live chat tool that offers visitor recording feature.
www.smartsupp.com Keyakinan 100%OWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.
owlcarousel2.github.io Keyakinan 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Keyakinan 100%FancyBox is a tool for displaying images, html content and multi-media in a Mac-style 'lightbox' that floats overtop of web page.
fancyapps.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260515-FE7639 Recipient: abuse@whiteprivacy.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.