exo-ds-web[.]pages[.]dev
Análisis de phishing y seguridad de exo-ds-web.pages.dev
“Exodus Wallet | Secure Cryptocurrency Wallet for Desktop & Mobile”
exo-ds-web.pages.dev — Accesible · acceso restringido (HTTP 403). Suplantación de marca: Ethereum; Tipo de estafa: Seed Phrase Theft. Resumen de las pruebas: VirusTotal 2/94 (ChainPatrol, Phishing Database); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of exo-ds-web.pages.dev indicates this domain was a short-lived phishing site impersonating Exodus Wallet, a cryptocurrency wallet service. The domain was registered on March 6, 2026, through Cloudflare, Inc., and resolved to IP 172.66.44.159, hosted on Cloudflare's network (AS13335) in the United States. The page title, 'Exodus Wallet | Secure Cryptocurrency Wallet for Desktop & Mobile,' directly mimics the branding of the legitimate Exodus service, aligning with the reported scam type of wallet/seed phishing. At the time of assessment, the domain appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL.
Two of 94 security vendors on VirusTotal flagged the domain as malicious. The domain's SSL certificate is issued by Google Trust Services (WE1), a common certificate authority used by both legitimate and malicious sites. The HTTP status returned a 403 error, suggesting the site may have been taken offline or restricted by the hosting provider. Infrastructure analysis reveals the use of Cloudflare nameservers (collins.ns.cloudflare.com and gannon.ns.cloudflare.com) and technologies such as HSTS and HTTP/3, which are consistent with modern web hosting but do not inherently indicate malicious intent.
The Gridinsoft trust score of 0/100 further corroborates the domain's classification as high-risk. Defenders should treat this domain as confirmed malicious, particularly in environments involving cryptocurrency transactions. While the domain is currently offline, historical DNS and WHOIS records should be preserved for forensic analysis. No evidence suggests this domain is part of a broader campaign, but defenders are advised to monitor for similar patterns involving Cloudflare-hosted pages impersonating cryptocurrency services.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of exo-ds-web.pages.dev · checked Apr 12, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.