Lompat ke laporan keamanan
Checked 09/08/2026 Ref 9C701CB6

MALICIOUS — CRITICAL

finovexus[.]com

PhishDestroy identifies finovexus.com as an active credential theft phishing site designed to harvest login credentials under the guise of a legitimate financial service.

92/100 evidence score · Critical
VirusTotal
6/91
Blocklists
No stored match
Ketersediaan
Terakhir diketahui aktif · HTTP 200
2026-05-15 08:40 UTCTerakhir diketahui aktif · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 6. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@whiteprivacy.com. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
2 months
Reports sent
1
Latest case ID
PD-20260515-FE7639
Current status
HTTP 200 at latest stored check
Jump to section
Ringkasan laporan

finovexus.com — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 6/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Netcraft); URLQuery 3 alerts; Spamhaus DBL_SPAM; PhishDestroy score 92/100. Registrar: Hosting Concepts.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Analysis

Ref 9C701CB6

PhishDestroy identifies finovexus.com as an active credential theft phishing site designed to harvest login credentials under the guise of a legitimate financial service. The domain mimics professional branding to trick users into entering sensitive information, likely targeting crypto wallets, banking portals, or investment platforms. Security researchers have observed this pattern in recent campaigns where threat actors rapidly register domains to evade takedown efforts. This domain was flagged by PhishDestroy after VirusTotal scanners confirmed elevated malicious activity—only 1 out of 95 security vendors detected the threat as of seed 9c701c. Technical indicators include a newly registered domain (March 27, 2026), hosting on IP 163.61.188.9, and registration through Hosting Concepts B.V. d/b/a Registrar.eu. The presence of a Let’s Encrypt SSL certificate suggests an attempt to appear legitimate, while the low detection rate highlights evasion tactics. Users who visited finovexus.com should immediately change passwords for any accounts exposed during the visit and enable multi-factor authentication where available. Scan devices for malware using reputable antivirus tools and monitor financial accounts for unauthorized transactions. Report the domain to your organization’s security team or file a complaint with the FBI IC3 if personal data was entered. Avoid reaccessing the site and warn others in your network to prevent further compromise.

VirusTotal
VirusTotal
6 det.
URLQuery
URLQuery
3 threat alerts
URLScan
URLScan
Gridinsoft
1/100
ScamAdviser
Scamadviser
1/100
Sertifikat TLS
Let's Encrypt
Usia
5 mo
Status terpantau
Terakhir diketahui aktif 200
PhishDestroy
Daftar Hapus
Terdaftar
Reports Sent
1
Cakupan data14 recorded checks
VirusTotal 6 / 91 URLQuery 3 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture laporan yang disimpan URLScan verdict Analisis selesai Pemblokiran DNS 14 diperiksa — tidak ada blokir TLS valid certificate, 89d WHOIS 5 mo old Tangkapan layar 3 captures · 3 sources Rantai pengalihan tidak diselidiki Gridinsoft 1/100 Scamadviser 1/100
Intelijen Keamanan Jaringan
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Private YARA rules maps.googleapis.com/maps-api-v3/api/js/64/14a/common.js audit Hunting_JS_WebAssembly
Private YARA rules www.youtube.com/s/player/2d01abf7/player_embed_es6.vflset/en_us/base.js audit Hunting_JS_WebAssembly
DNS4EU finovexus.com malicious Sinkholed

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
10/11
Sent Report Recorded
Stored sent-report record for registrar Hosting Concepts B.V. d/b/a Registrar.eu, hosting provider, 2 abuse contacts
abuse@whiteprivacy.comabuse@registrar.eu
15/05/2026

Status Daftar Blokir Publik

Tangkapan tersimpan

Judul Halaman
Finovex
Sertifikat TLS
Valid transport encryption · Diterbitkan oleh Let's Encrypt · valid for 89 days

Intelijen Domain

Domain
URLScan Verdict Analisis selesai score 0 report ↗
Telegram IoCs 1 extracted https://t.me/finovexadmin
Server / ASN LiteSpeed · AS153568 NEW DHAKA HARDWARE
Reputasi IP abuse score 33/100 47 reports checked 13/07/2026
Registrar Hosting Concepts NG(NG)
Alamat IP 163.61.188.9 US
LokasiUS Staten Island, US
JaringanAS153568 · MIT
PendaftaranDibuat 27/03/2026 (135d)
Elapsed Since First Report 2 days
Yang kami hitung Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Terakhir diketahui aktif.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
Status HTTP200
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi15/05/2026
IoC Extractionscanned 29/07/20260 wallet · 1 Telegram IoC
Submitted URLhttps://finovexus.com/
Server namadns1.lytehosting.comdns2.lytehosting.comdns3.lytehosting.comdns4.lytehosting.com
TLS Fingerprint
TLS Observationvalid from 14/05/2026scanned 15/05/2026
Favicon Hash
Case ID
ICANN OVERSIGHT

Akreditasi dan konteks RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Tidak ada yang dikirim secara otomatis.
Teknologi · 12 identified
particles.js
JavaScript graphics

Particles.js is a JavaScript library for creating particles.

github.com Keyakinan 100%
Chart.js
JavaScript graphics

Chart.js is an open-source JavaScript library that allows you to draw different types of charts by using the HTML5 canvas element.

www.chartjs.org 75% confidence
YouTube
Video players

YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.

www.youtube.com Keyakinan 100%
Bootstrap
UI frameworks

Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.

getbootstrap.com Keyakinan 100%
LiteSpeed
Web servers

LiteSpeed is a high-scalability web server.

litespeedtech.com Keyakinan 100%
Unpkg
CDN

Unpkg is a content delivery network for everything on npm.

unpkg.com Keyakinan 100%
Smartsupp
Live chat

Smartsupp is a live chat tool that offers visitor recording feature.

www.smartsupp.com Keyakinan 100%
Slick
JavaScript libraries
kenwheeler.github.io Keyakinan 100%
OWL Carousel
JavaScript libraries

OWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.

owlcarousel2.github.io Keyakinan 100%
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com Keyakinan 100%
FancyBox
JavaScript libraries

FancyBox is a tool for displaying images, html content and multi-media in a Mac-style 'lightbox' that floats overtop of web page.

fancyapps.com Keyakinan 100%
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org Keyakinan 100%
Detected via Cloudflare Radar · Wappalyzer engine
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

6 / Vendor keamanan 91 menandai domain ini
View on VT
Last analyzed Previous stored snapshot: 6 detections
alphaMountain.ai
CRDF
Fortinet
Gridinsoft
Netcraft
SOCRadar
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri
Sematkan Laporan IniRead-only HTML widget
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/finovexus.com"
  title="PhishDestroy threat report for finovexus.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Surat Terima Kasih yang Sangat Tulus

Pembuat draf satir

Penerima
Konteks biaya

Draf satir. Angka biaya merupakan perkiraan; tidak diklaim bahwa angka tersebut secara tepat terkait dengan domain ini.