exodulogjuiui[.]gitbook[.]io
“Exodus® Login*: A Comprehensive Solutionage | us”
Evidence Summary
This domain, exodulogjuiui.gitbook.io, is actively serving a credential‑phishing campaign that impersonates the Exodus brand. The site was originally registered on 30 March 2014 through Cloudflare, Inc., and continues to use Cloudflare’s infrastructure; DNS resolves to 104.18.40.47, an address owned by AS13335 Cloudflare, Inc. in the United States. The domain is fronted by Cloudflare’s DNS service (dahlia.ns.cloudflare.com, hugh.ns.cloudflare.com) and delivers traffic over HTTP/3 with a 307 redirect response. TLS termination is handled by a Google Trust Services certificate (WE1), indicating a valid‑looking HTTPS connection. The page title returned by the server reads “Exodus® Login*: A Comprehensive Solutionage | us”, directly referencing Exodus and suggesting a login‑capture page. Independent security vectors have already flagged the domain: it appears on three blocklists, is blocked by PhishDestroy, MetaMask, and SEAL, and 17 of 91 VirusTotal scanners have marked it malicious. The combination of brand impersonation, credential‑phishing intent, and persistent active status elevates its risk to high. Defenders should add the domain to deny‑list rules, monitor for any traffic to the associated IP, and enforce strict verification of Exodus‑related communications. Continuous observation of changes to DNS records or certificate details is also advised.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
8 monitored external feeds No match
Detection timeline
-
VirusTotal
16 → 17
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive