MALICIOUS — HIGH
exodus-us-web3[.]pages[.]dev
Analysis of the domain exodus-us-web3.pages.dev indicates a confirmed brand impersonation targeting Exodus, a cryptocurrency wallet provider.
- VirusTotal
- 1/94
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Raggiungibile · accesso limitato · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
exodus-us-web3.pages.dev — Raggiungibile · accesso limitato (HTTP 403). Simulazione del marchio: Exodus; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 1/94 (ChainPatrol); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Cloudflare Pages.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Analysis of the domain exodus-us-web3.pages.dev indicates a confirmed brand impersonation targeting Exodus, a cryptocurrency wallet provider. The domain was registered on March 11, 2026, through Cloudflare Pages and is currently offline, returning an HTTP 403 status. Infrastructure analysis reveals it resolves to IP 172.66.44.139, hosted on AS13335 (Cloudflare, Inc.) in the US. Nameservers are aldo.ns.cloudflare.com and karsyn.ns.cloudflare.com, consistent with Cloudflare's infrastructure. The SSL certificate is issued by Google Trust Services (WE1), a common certificate authority for Cloudflare-hosted domains.
Detection data shows the domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL. Gridinsoft assigns a trust score of 0/100, reinforcing its malicious classification. VirusTotal reports a single detection from 94 security vendors, though this number may not reflect the full scope of its threat status. The page title, 'Suspected phishing site | Cloudflare,' further supports its classification as a crypto scam, aligning with the known scam type specified in available intelligence.
No evidence of a specific phishing kit or exact page content is present in the data, limiting further technical breakdown of the attack vector. Defenders should treat this domain as a confirmed malicious resource and ensure it is blocked at the DNS or network level. Given its offline status, monitoring for reactivation or similar domains using the same infrastructure (Cloudflare Pages, identical nameservers) is recommended. The domain's creation date and rapid inclusion on blocklists suggest a short-lived but targeted campaign, typical of crypto-related phishing operations.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of exodus-us-web3.pages.dev · checked Apr 30, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.