exxodus--web[.]pages[.]dev
فحص التصيد والأمان للنطاق exxodus--web.pages.dev
“exxodus--web.pages.dev”
exxodus--web.pages.dev — يمكن الوصول إليها · الوصول مقيد (HTTP 403). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VT 13/94 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 99/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed exxodus--web.pages.dev on Mar 16, 2026. Positive findings were recorded by VirusTotal, MetaMask, and SEAL. Evidence score: 99/100.
VirusTotal recorded 13 detections among 94 engines: ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet, G-Data on Jul 18, 2026 at 18:45 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. On Mar 16, 2026 at 14:26 UTC, Google Safe Browsing returned no flag; PhishStats returned no feed match. URLScan completed without a malicious verdict (score 0) on Mar 24, 2026 at 11:15 UTC.
An access-restricted HTTP 403 response was recorded on Aug 7, 2026 at 01:02 UTC. Registration records list Cloudflare, Inc. as the registrar and Sep 17, 2025 as the registration date. At collection time, the domain resolved to 172.66.44.212. Captured page title: “exxodus--web.pages.dev”. PhishDestroy classified the observed content as Credential Phishing. DOM analysis completed on Mar 23, 2026 at 23:10 UTC; stored DOM score 0/100. IoC extraction completed on Aug 1, 2026 at 04:22 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis25/07/2026
Analysis of exxodus--web.pages.dev, observed as a credential‑phishing site, shows that the domain was registered on September 18 2025 through Cloudflare, Inc. The authoritative nameservers are nucum.ns.cloudflare.com and sage.ns.cloudflare.com, both belonging to Cloudflare’s DNS infrastructure. DNS resolution points to the IP address 172.66.44.212, which is announced by AS13335, the Cloudflare network, and geolocated to the United States. The TLS certificate presented is issued by Google Trust Services, confirming the use of a legitimate, publicly trusted certificate chain. HTTP responses return a 403 status code, and the server advertises HSTS and HTTP/3, indicating a modern Cloudflare edge configuration.
Reputation data is strongly negative: Gridinsoft assigns a trust score of 0 / 100, and the domain appears on three independent security blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis reports that 13 of 94 scanning engines have flagged the domain, reinforcing the malicious assessment. The page title returned by the server is identical to the domain name, providing no additional context.
The primary threat classification is credential phishing, though the specific targeted service or brand is not disclosed in the collected metadata. The site is currently taken offline, which limits real‑time observation but does not remove the historical risk. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑registration or re‑use of the same IP space, and update detection signatures to incorporate the observed HSTS/HTTP‑3 fingerprint and the Cloudflare‑issued certificate details. Additional investigation may be required to locate any associated phishing landing pages or payloads that were previously hosted under this domain.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of exxodus--web.pages.dev · checked Mar 16, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: exxodus--web.pages.dev
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “exxodus--web.pages.dev”.
اعتبارًا من 07/08/2026، كان لدى exxodus--web.pages.dev اكتشافات من محركات الأمان 13.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب