portal-en-exdua-web[.]pages[.]dev
“Exodus Wallet - Secure Multi-Asset Cryptocurrency Wallet”
portal-en-exdua-web.pages.dev — Konten tidak tersedia. Peniruan identitas merek: Across; Jenis penipuan: Seed Phrase Theft. Ringkasan bukti: VirusTotal 7/94 (ADMINUSLabs, ChainPatrol, CyRadar, Fortinet, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Registrar: Cloudflare.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of portal-en-exdua-web.pages.dev (seed de9d71) indicates that the domain was registered on March 6, 2026 through Cloudflare, Inc. and is hosted on the Cloudflare network (ASN 13335) with the IP address 172.66.44.98 located in the United States. The authoritative name servers chan.ns.cloudflare.com and norman.ns.cloudflare.com resolve to the same infrastructure, confirming that the operator leveraged Cloudflare’s DNS and CDN services. The site presents the page title “Exodus Wallet – Secure Multi-Asset Cryptocurrency Wallet”, and the declared scam type is Wallet/Seed Phishing, targeting users of cryptocurrency wallets. The brand target is listed as “across”, indicating a broad impersonation attempt rather than a single brand.
The domain is currently offline, returning an HTTP 403 status code, and is listed on three security blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL, reflecting consensus among anti-phishing products that the domain is malicious. VirusTotal analysis shows that seven of ninety-four scanners flagged the domain, reinforcing the detection consensus. The SSL certificate is issued by Google Trust Services under the WE1 hierarchy, which is typical for Cloudflare‑issued certificates and does not provide a trust advantage for the malicious actor.
A Gridinsoft trust score of 0 out of 100 further emphasizes the high risk associated with the site. Defenders encountering traffic to this domain should block the resolved IP address 172.66.44.98 and the full hostname, update web filtering rules to include the three identified blocklists, and enforce client‑side warnings for any content that claims to be an Exodus wallet login page. Continuous monitoring of Cloudflare‑originated domains is advised, as the service can be abused for short‑lived phishing infrastructure. Because the site is already offline, immediate incident response may focus on containment of any credential harvesting that could have occurred before takedown.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of portal-en-exdua-web.pages.dev · checked Mar 26, 2026
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive