# doc--exdus-web3.pages.dev — SUSPICIOUS > PhishDestroy identifies doc--exdus-web3.pages.dev as a Web3 phishing page hosted on Cloudflare. 1/95 security vendors flagged this threat. Check the full report. ## Summary PhishDestroy identifies doc--exdus-web3.pages.dev as a live phishing domain designed to impersonate a legitimate Web3 service, specifically targeting users of decentralized platforms. This domain leverages Cloudflare Pages infrastructure to host malicious content, presenting visitors with counterfeit login pages that harvest cryptocurrency wallet credentials and private keys under the guise of a Web3 authentication portal. The threat is considered elevated due to its active status and abuse of a trusted hosting provider to lend false legitimacy to the scam. This domain was flagged by PhishDestroy with 1 out of 95 security vendors on VirusTotal detecting the threat at the time of analysis. It resolves to IP address 188.114.96.3 and is associated with a Google Trust Services SSL certificate, further enhancing its appearance of credibility. The domain operates through Cloudflare, Inc., a legitimate hosting provider that has been exploited to distribute phishing content. Additionally, the use of a Pages.dev subdomain structure is a common tactic to mimic official documentation or service portals, increasing the likelihood of user deception. Users who visited doc--exdus-web3.pages.dev should immediately disconnect from the site, avoid entering any credentials or cryptocurrency wallet information, and scan their devices for malware. If any sensitive data was entered, users are advised to revoke any exposed API keys, wallet passwords, or seed phrases, and transfer remaining funds to a newly generated wallet. Report the incident to your cybersecurity team or platform provider, and consider blocking the domain and associated IP (188.114.96.3) at the network level to prevent further exposure. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/594f81e0-acec-43bf-a9f2-456edf0945de - PhishDestroy: https://phishdestroy.io/domain/doc--exdus-web3.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/doc--exdus-web3.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/doc--exdus-web3.pages.dev/ Last updated: 2026-03-22