exodus-webb[.]pages[.]dev
Analyse phishing et sécurité de exodus-webb.pages.dev
“Exodus Web3 Wallet | Getting Started Guide”
exodus-webb.pages.dev — Accessible · accès restreint (HTTP 403). Usurpation de l'identité de la marque : Exodus; Type d'arnaque : Crypto Drainer. Résumé des preuves: VirusTotal 3/93 (ChainPatrol, Kaspersky, Phishing Database); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain exodus-webb.pages.dev was registered on March 02, 2026 through Cloudflare, Inc. and is currently offline, returning an HTTP 403 status code. DNS resolution points to the Cloudflare edge address 172.66.47.198, with authoritative nameservers addilyn.ns.cloudflare.com and robert.ns.cloudflare.com. The site employed HSTS, HTTP/3, and presented a Google Trust Services / WE1 SSL certificate, indicating a legitimate‑looking TLS configuration. The page title observed before takedown was "Exodus Web3 Wallet | Getting Started Guide," directly referencing the Exodus brand and suggesting a wallet or seed‑phishing campaign.
Security telemetry shows the domain is listed on three blocklists, has a Gridinsoft trust score of 0 / 100, and was flagged by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis recorded three detections out of ninety‑three scanners, reinforcing the malicious classification. The infrastructure is hosted on Cloudflare’s AS13335 network in the United States, a common choice for short‑lived phishing sites. Defenders should immediately denylist the domain and any future subdomains under pages.dev that reference Exodus or wallet terminology.
Network monitoring rules should be updated to alert on DNS queries to addilyn.ns.cloudflare.com or robert.ns.cloudflare.com resolving to 172.66.47.198. Email and web gateway filters ought to block URLs containing the observed page title or similar phrasing. Users of the Exodus wallet should be reminded to verify official URLs and to never disclose seed phrases to any site not hosted on exodus.com. Continuous threat‑intel feeds should be consulted for new domains employing the same branding pattern, as the rapid creation date suggests a likely repeat‑offender.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of exodus-webb.pages.dev · checked Apr 14, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif