# exobus-us.pages.dev — SUSPICIOUS > exobus-us.pages.dev is a suspected crypto drainer with 0/95 VirusTotal detections. Verify its legitimacy on PhishDestroy before sharing any wallet details. ## Summary PhishDestroy identifies exobus-us.pages.dev as a potentially malicious domain currently under investigation for generic phishing activities. This site poses a significant risk to users who may interact with it, particularly due to its suspected involvement in cryptocurrency drainer schemes. A crypto drainer is a type of malicious webpage designed to trick visitors into connecting their digital wallets under false pretenses, such as fake giveaways, airdrops, or investment opportunities. Once connected, the drainer can silently siphon off cryptocurrency assets without the user’s knowledge, leading to irreversible financial losses. This domain was flagged with a risk level of 'under_investigation' due to its active status and the absence of detections across 95 security vendors on VirusTotal, as recorded on seed 1565bc. It was registered through Cloudflare, Inc., a common choice for malicious actors seeking anonymity and fast domain provisioning. The domain resolves to the IP address 188.114.96.3 and utilizes a Google Trust Services SSL certificate, which may lend it an air of legitimacy to unsuspecting visitors. Notably, the lack of detections on VirusTotal suggests that this domain may be newly active or employing evasion techniques to bypass initial scans. If you have visited exobus-us.pages.dev, immediately disconnect any connected cryptocurrency wallets and revoke any permissions granted to suspicious domains. Do not enter any personal information, including wallet addresses or private keys, into the site. Run a full system scan using updated antivirus software to check for any lingering malware. Report the domain to PhishDestroy for further analysis and share your findings to help others stay safe. Always verify the legitimacy of websites, especially those promoting financial opportunities, by cross-referencing reviews and checking for red flags such as newly registered domains or mismatched SSL certificates. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/8618d06b-01d1-45bb-a012-7abc0e91b094 - PhishDestroy: https://phishdestroy.io/domain/exobus-us.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/exobus-us.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/exobus-us.pages.dev/ Last updated: 2026-03-22