exodus-tools[.]at
“Exodus Web3 Wallet”
Ringkasan bukti
Analysis of exodus-tools.at shows a short‑lived domain created on 21 February 2026 and hosted on a Russian address (185.212.148.138, AS204997 FIRST SERVER LIMITED). The domain resolves to three dnspod.com name servers (a.dnspod.com, b.dnspod.com, c.dnspod.com) and is registered through Hosting Concepts B.V. d/b/a Registrar.eu. The TLS certificate is issued by Let’s Encrypt (R13), indicating a publicly available certificate without any extended validation. The page title returned from the site, when it was online, was “Exodus Web3 Wallet”, and the domain was explicitly listed as impersonating the Exodus brand, fitting a crypto‑scam profile.
VirusTotal scans recorded 15 detections out of 93 security vendors, confirming that multiple AV engines flagged the domain as malicious. Independent blocklists used by PhishDestroy, MetaMask and SEAL have also listed the domain, and it appears on three additional security blocklists. The site has since been taken offline, but the historical evidence suggests it was used to lure victims into providing cryptocurrency wallet credentials or transferring funds. Defenders should continue to block the IP address 185.212.148.138 and the associated ASN (AS204997) at the network perimeter.
Email and web filtering rules should be updated to drop any traffic to exodus-tools.at, and any detection signatures that reference the Let’s Encrypt certificate fingerprint or the specific page title “Exodus Web3 Wallet” should be incorporated. Because the domain was registered recently, threat actors may reuse the same registrar or name‑server pattern for future campaigns; monitoring for new domains using the same dnspod.com name servers or Registrar.eu registration details is advisable. Until further forensic artifacts become available, the current evidence is sufficient to classify the domain as a high‑risk crypto‑scam targeting Exodus users.
Data Coverage
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 12/08/2026
Linimasa deteksi
-
Status domain
Dapat dijangkau → Tidak dapat dijangkau
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive