exodus[.]ghost[.]io
“Exodus | Best Bitcoin Wallet | BTC Wallet App 💎”
Observación almacenada
Contraste de títulos observado
Resumen de las pruebas
Analysis of exodus.ghost.io shows a domain that has been identified as an impersonation of the Exodus cryptocurrency wallet brand. The domain resolves to IP address 151.101.3.7, which belongs to the Fastly, Inc. network (AS54113) located in the United States. The hosting stack reports Varnish, Nginx and OpenResty, and the site presents an HTTPS certificate issued by Let’s Encrypt (R12). The page title returned by the server is "Exodus | Best Bitcoin Wallet | BTC Wallet App 💎", matching the Exodus brand name and suggesting a wallet‑or‑seed phishing motive. The domain is currently marked offline, returns an HTTP 404 status, and is listed on a single security blocklist.
It is also flagged by PhishDestroy, indicating that defensive feeds have already captured it. The registrar is listed as 1API GmbH, and the domain was created on 01 Oct 2011, showing a long‑standing registration that predates the recent malicious activity. The nameservers woz.ns.cloudflare.com and sara.ns.cloudflare.com are Cloudflare‑managed, a common choice for both legitimate and malicious operators. A Gridinsoft trust score of 0 / 100 reinforces the classification as high‑risk. VirusTotal records show the domain was scanned by 95 vendors, none of which currently flag it, but the absence of detections does not constitute assurance of safety.
The evidence points to a targeted brand‑impersonation campaign aimed at harvesting cryptocurrency wallet seeds. Defenders should continue to block the domain at perimeter filters, monitor the associated IP 151.101.3.7 for any resurgence of activity, and add the domain to internal threat‑intel repositories. Given the low trust score and the presence on blocklists, any inbound traffic to this host should be treated as malicious, and users should be warned against any credential or seed entry attempts that reference Exodus.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Tecnologías
3 tecnologías identificadas con alta confianza
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of exodus.ghost.io · checked Mar 2, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.