exaudiaslogin[.]gitbook[.]io
“Exodus®* Login : A Comprehensive Solution | us”
Résumé des preuves
Analysis indicates that exaudiaslogin.gitbook.io is an active credential-phishing domain flagged by multiple security vendors as of August 2026. The domain, registered on March 30, 2014, is hosted on Cloudflare infrastructure, resolving to IP address 172.64.147.209 with nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. It appears on three security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, suggesting targeted credential-harvesting activity. VirusTotal reports that 3 out of 91 security vendors detect this domain as malicious, though the exact nature of the phishing content remains unconfirmed due to limited page-level analysis.
Infrastructure analysis reveals the domain leverages Cloudflare’s services, a common tactic to obscure hosting origins and evade takedowns. The long registration period (over a decade) does not mitigate risk, as phishing domains frequently exploit aged registrations to appear legitimate. No SSL certificate anomalies or HTTP status errors are reported, but this is consistent with modern phishing campaigns that prioritize operational uptime. The absence of additional context—such as the targeted brand, phishing kit, or specific lures—limits attribution, though the domain’s inclusion in MetaMask’s blocklist implies potential cryptocurrency-related credential theft.
Defenders should treat this domain as high-risk. Immediate actions include blocking the domain and its resolving IP at the network perimeter, updating endpoint protection rules, and monitoring for credential submissions or redirects to exaudiaslogin.gitbook.io. If this domain is linked to internal user reports, incident response teams should prioritize password resets for affected accounts and review logs for unauthorized access attempts. Given its active status and blocklist presence, further investigation into associated infrastructure (e.g., linked domains, hosting patterns) is recommended to identify broader campaign activity.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
8 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Première observation
Première valeur enregistrée : Accessible
Technologies
7 technologies identifiées avec une forte confiance
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of exaudiaslogin.gitbook.io · checked Aug 4, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif