EN ES PT
Back to Stats

Captura Visual

Screenshot of www.demon.web3securenetwork.com

Información de Detección

https://www.demon.web3securenetwork.com
Detected Brand
Finovon (Possible)
Country
International
Confianza
100%
HTTP Status
200
Report ID
f36e95a6-62a…
Analyzed
2026-02-01 10:19
Final URL (after redirects)
https://www.demon.web3securenetwork.com/

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T15FB273786240597E61CBC2B2FA65AF39F299C387DD17A28FD2E8C3251797C40CD96390
CONTENT ssdeep
384:ORdufKqGouBSIqfEQp4h7WaqVXhg5XRhgv1Bv6OsGcxWWauIc+pNC:yduf5OQXhg5XRhgv1BvvsGcxRYNC

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
bf1edaf0e0cbc060
VISUAL aHash
9d1c37b5c3e7bfab
VISUAL dHash
79756d619e8e5a4a
VISUAL wHash
9d0415a1c3e7abab
VISUAL colorHash
0700000001a
VISUAL cropResistant
79756d619e8e5a4a

Análisis de Código

Risk Score 76/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Personal Info

🔬 Threat Analysis Report

• Amenaza: Phishing
• Objetivo: Usuarios de criptomonedas
• Método: Suplantación de la cartera Finovon
• Exfil: Probablemente a través de envíos de formularios u otras acciones.
• Indicadores: Dominio sospechoso, ofuscación.
• Riesgo: Alto

🔒 Obfuscation Detected

  • fromCharCode
  • unicode_escape

🎯 Kit Endpoints

  • https://www.demon.web3securenetwork.com/login

📡 API Calls Detected

  • offline

📊 Desglose de Puntuación de Riesgo

Total Risk Score
95/100

Contributing Factors

Suspicious Domain
The domain does not relate to the supposed brand 'Finovon' and is suspicious.
Obfuscation
The code is obfuscated which hides malicious intent
Brand Impersonation
The website layout and content is closely mimicking the layout of a legitimate wallet.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Two-Factor Authentication Stealer
Objetivo
Finovon (Possible) users (International)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltración
Form submission (backend endpoint not detected - likely JavaScript-based)
Evaluación de Riesgo
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Personal Info
  • 18 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Finovon
Fake Service
Finovon Wallet

⚔️ Metodología de Ataque

Primary Method: Brand impersonation

The attacker attempts to replicate a trusted service to steal credentials or sensitive data.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
demon.web3securenetwork.com
Registered
None
Registrar
None
Estado
Active

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
399,2 KB

🔗 API Endpoints Detected

Other
5

🔐 Obfuscation Detected

  • : Moderate
  • : None

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.