# doc-us-exxdos.pages.dev — MALICIOUS > Check the safety of doc-us-exxdos.pages.dev. High-risk phishing domain now offline and blocked to protect users from scams. ## Summary PhishDestroy identifies doc-us-exxdos.pages.dev as a high-risk phishing domain designed to deceive users and steal sensitive information. This type of threat is critical because it can lead to financial loss, data breaches, and compromised personal credentials. The domain was created recently on February 21, 2026, and was registered through Cloudflare, Inc. It resolved to IP address 172.66.45.8, and appeared on two security blocklists, with 14 out of 95 security vendors flagging it on VirusTotal. The site was taken offline promptly and displayed a 'Suspected phishing site' warning by Cloudflare, indicating swift mitigation efforts. Users should avoid visiting doc-us-exxdos.pages.dev or interacting with any related links or emails. Security best practices include updating antivirus software, remaining cautious with unsolicited communications, and reporting suspicious sites to cybersecurity teams. PhishDestroy recommends vigilance to prevent falling victim to phishing scams associated with this domain. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 403) - Page title: Suspected phishing site | Cloudflare ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: Cloudflare, Inc. - Country: US - IP: 172.66.45.8 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["emerie.ns.cloudflare.com", "vasilii.ns.cloudflare.com"] - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 14 vendors flagged Vendors: ["ADMINUSLabs", "ChainPatrol", "alphaMountain.ai", "BitDefender", "Chong Lua Dao", "Emsisoft", "Fortinet", "G-Data", "Kaspersky", "Lionic", "Netcraft", "Sophos", "Trustwave", "Webroot"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019c34e0-eb90-7720-afec-801c6c10e138.png - Cloudflare Radar: https://radar.cloudflare.com/scan/efc57e74-5e75-48d6-823f-30861f4708fe - PhishDestroy: https://phishdestroy.io/domain/doc-us-exxdos.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/doc-us-exxdos.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/doc-us-exxdos.pages.dev/ Last updated: 2026-03-19