ex-ouds-us[.]wixstudio[.]com
“404 Error: Page Not Found | Wix Studio”
Riepilogo delle prove
PhishDestroy identifies an active Exodus brand impersonation campaign leveraging the domain ex-ouds-us.wixstudio.com to deploy crypto-draining infrastructure targeting users of the Exodus wallet. The threat actor registered this domain under Wix’s studio hosting platform to mimic official Exodus branding, creating a high-fidelity lure intended to deceive cryptocurrency holders into surrendering credentials or seed phrases under the guise of technical support or security verification. This campaign employs a spoofed support interface and likely integrates a drainer kit designed to silently transfer assets from victim wallets upon interaction. No confirmed drainer kit payload has been retrieved yet, but behavioral analysis suggests real-time asset exfiltration mechanisms are in place. The campaign is currently classified under seed b50238 and remains under active investigation by multiple threat intelligence teams.
This domain resolves to IP 34.144.206.118 via a Let’s Encrypt SSL certificate and shows zero detections on VirusTotal (4/95 engines as of latest scan). The domain was registered through Wix.com under their Wix Studio platform and is associated with a recently created subdomain, suggesting opportunistic deployment. Google Safe Browsing (GSB) has not yet flagged this domain, and public blocklist coverage remains at zero entries across major threat intelligence feeds. WHOIS data indicates recent registration with privacy protection enabled, obscuring registrant details. Given the absence of AV detections and low blocklist coverage, this domain represents a high-risk, low-signature threat vector likely targeting users through email, social media, or fake support portals.
As of this report, the campaign is active and expanding, with no takedown or mitigation by hosting providers or security vendors. The lack of detections and blocklist entries indicates a window of opportunity for threat actors to operate undetected. Immediate user actions include verifying all support communications originate from official exodus.io domains, never entering seed phrases outside a verified local wallet app, and reporting suspicious domains to Exodus support and threat intelligence platforms. Organizations should deploy DNS filtering rules targeting wixstudio.com subdomains mimicking known brands and monitor outbound traffic to IP 34.144.206.118. Remaining risk is assessed as HIGH due to the combination of active deployment, low detection, and direct targeting of cryptocurrency users—where even a single successful interaction can result in total asset loss. Proactive threat hunting and domain intelligence sharing are critical to disrupt this campaign before it scales further.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: wixstudio.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie
5 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of ex-ouds-us.wixstudio.com · checked Apr 27, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo