regist-exodus[.]com
“Exodus: the world's leading bitcoin and crypto wallet”
Riepilogo delle prove
The domain regist-exodus.com was registered on February 21, 2026 and is currently reported as taken offline. Technical analysis shows that it resolves to the IPv6 address 2606:4700:4408::6812:24d4, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The site presented the page title "Exodus: the world's leading bitcoin and crypto wallet," directly referencing the Exodus brand, indicating a clear case of brand impersonation aimed at cryptocurrency users. The domain appears on three security blocklists—PhishDestroy, MetaMask, and SEAL—demonstrating that multiple threat‑intelligence providers have identified it as malicious.
VirusTotal scans recorded two detections out of ninety‑three participating security vendors, providing additional confirmation of its suspicious nature. The SSL certificate associated with the domain is identified as WE1, though no further certificate details are available. While the site is presently offline, the existing indicators suggest it was used for a crypto‑related scam, likely to harvest credentials or lure victims into fraudulent transactions.
Uncertainties remain regarding the exact payload, the specific phishing page layout, and whether any additional infrastructure was employed. Defenders should continue to block regist-exodus.com at network perimeters, update URL filtering and DNS threat‑intel feeds with the observed indicators, and monitor for new domains that reuse the same brand name or similar IP ranges. Ongoing observation of Cloudflare‑hosted IPv6 addresses linked to this activity is recommended to detect any re‑activation or migration of the campaign.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.exodus.com/_next/static/chunks/80507811.7cd4545731387f40.js?dpl=dpl_8ffzu8ta94flpgl8xudhhbab1yar |
audit | Hunting_JS_WebAssembly |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo