exodus-wellt[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
The domain exodus-wellt.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and resolves to the IPv6 address 2a06:98c1:3120::3, which is announced by AS13335 (Cloudflare, Inc.) and geolocated to the United States. The site is currently offline, returning HTTP 403 responses, and its page title is "Suspected phishing site | Cloudflare". Technical fingerprinting shows the presence of HSTS, Cloudflare edge services, and HTTP/3, while the TLS certificate is issued by Google Trust Services under the WE1 root. The domain is listed on three external security blocklists and is blocked by PhishDestroy, MetaMask, and SEAL.
VirusTotal scans report nine positive detections out of ninety-three vendor engines, indicating consensus among security products that the domain is malicious. Additional risk indicators include a Gridinsoft trust score of 0 out of 100 and a classification as a "Crypto Scam" targeting the Exodus brand. Nameserver records point to adi.ns.cloudflare.com, grant.ns.cloudflare.com, karl.ns.cloudflare.com, and kristin.ns.cloudflare.com, confirming the use of Cloudflare's DNS infrastructure.
While the offline status prevents direct content analysis, the combination of brand impersonation, malicious detection counts, blocklist presence, and low trust scoring suggests a high likelihood of credential harvesting or crypto‑related fraud. Defenders should continue to block the domain at network perimeter devices, update URL filtering feeds with the observed indicators, and monitor for any re‑registration attempts or variations that reuse the same nameserver set or TLS fingerprint. Incident response teams should also alert users of the Exodus platform about the attempted impersonation and advise verification of any unsolicited communications referencing the brand.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of exodus-wellt.pages.dev · checked Apr 11, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo