# help-doc-exodusweb3.pages.dev — MALICIOUS > help-doc-exodusweb3.pages.dev is under phishing investigation. Avoid sharing personal info and verify site legitimacy before interacting. ## Summary PhishDestroy identifies help-doc-exodusweb3.pages.dev as a domain currently classified under generic phishing suspicion. Although it has not yet been confirmed as malicious, the domain is actively monitored due to its suspicious naming pattern mimicking legitimate Exodus wallet support pages, which could potentially mislead users into divulging sensitive data. From a technical standpoint, the domain is registered via Cloudflare, Inc., which is commonly used for proxying and content delivery. It resolves to the IP address 172.66.47.85. VirusTotal scans show zero detections from 95 security vendors, indicating no immediate signatures of malware or phishing are recognized. However, the domain’s recent registration and the usage of a Cloudflare-hosted pages.dev subdomain contribute to the ongoing caution. No additional blocklist or threat intelligence pulses currently flag this domain. The status of help-doc-exodusweb3.pages.dev remains active and under investigation by PhishDestroy. Users are advised to exercise caution and avoid entering personal or financial information until further verification is complete. PhishDestroy will continue monitoring this domain for any emerging indicators to better assess its risk level and provide updated guidance. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 403) - Target brand: Exodus - Page title: Exódus® Web3 Wallet | Exódus® Browser Extension — Presentation ## Domain Intelligence - Registered: 2026-03-07 11:07:02 - Registrar: Cloudflare, Inc. - Country: US - IP: 172.66.47.85 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: cosmin.ns.cloudflare.com dana.ns.cloudflare.com - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 10 vendors flagged Vendors: ["ADMINUSLabs", "ChainPatrol", "BitDefender", "CyRadar", "Fortinet", "G-Data", "Kaspersky", "Lionic", "Phishing Database", "Sophos"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cc7cd-a1eb-705a-a5f8-c24eaf62ff80.png - Wayback Machine: https://web.archive.org/web/https://help-doc-exodusweb3.pages.dev - PhishDestroy: https://phishdestroy.io/domain/help-doc-exodusweb3.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/help-doc-exodusweb3.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/help-doc-exodusweb3.pages.dev/ Last updated: 2026-03-19