exodus-tools[.]at
“Exodus Web3 Wallet”
Zusammenfassung der Beweislage
Analysis of exodus-tools.at shows a short‑lived domain created on 21 February 2026 and hosted on a Russian address (185.212.148.138, AS204997 FIRST SERVER LIMITED). The domain resolves to three dnspod.com name servers (a.dnspod.com, b.dnspod.com, c.dnspod.com) and is registered through Hosting Concepts B.V. d/b/a Registrar.eu. The TLS certificate is issued by Let’s Encrypt (R13), indicating a publicly available certificate without any extended validation. The page title returned from the site, when it was online, was “Exodus Web3 Wallet”, and the domain was explicitly listed as impersonating the Exodus brand, fitting a crypto‑scam profile.
VirusTotal scans recorded 15 detections out of 93 security vendors, confirming that multiple AV engines flagged the domain as malicious. Independent blocklists used by PhishDestroy, MetaMask and SEAL have also listed the domain, and it appears on three additional security blocklists. The site has since been taken offline, but the historical evidence suggests it was used to lure victims into providing cryptocurrency wallet credentials or transferring funds. Defenders should continue to block the IP address 185.212.148.138 and the associated ASN (AS204997) at the network perimeter.
Email and web filtering rules should be updated to drop any traffic to exodus-tools.at, and any detection signatures that reference the Let’s Encrypt certificate fingerprint or the specific page title “Exodus Web3 Wallet” should be incorporated. Because the domain was registered recently, threat actors may reuse the same registrar or name‑server pattern for future campaigns; monitoring for new domains using the same dnspod.com name servers or Registrar.eu registration details is advisable. Until further forensic artifacts become available, the current evidence is sufficient to classify the domain as a high‑risk crypto‑scam targeting Exodus users.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt