faqe-exodusd-com[.]typedream[.]app
“500: Internal Server Error”
faqe-exodusd-com.typedream.app — 확인되지 않음. 브랜드 사칭: Exodus; 사기 유형: Impersonation. 증거 요약: VirusTotal 2/91 (ChainPatrol, alphaMountain.ai); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. 등록기관: Typedream.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
faqe-exodusd-com.typedream.app was observed hosting a brand‑impersonation campaign targeting users of the Exodus cryptocurrency wallet. The site was provisioned through the Typedream website‑builder platform, which issues SSL certificates from Google Trust Services under the WE1 profile. Network analysis shows the domain resolved to the Cloudflare‑owned address 188.114.96.3, a location attributed to Canada. HTTP requests returned a 500 Internal Server Error, and the page title reflected the same error message, indicating that the malicious front‑end is no longer serving content.
VirusTotal scans recorded detections by 2 of 91 security vendors, and the domain appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL. The infrastructure was also flagged by brand‑specific protection services for impersonating Exodus. Nameserver data could not be retrieved (NS_NOT_FOUND). The domain has been taken offline at the time of reporting, but historical activity suggests that the attacker leveraged the Typedream hosting environment to quickly spin up a credential‑harvesting page that mimicked Exodus branding.
At present no active phishing page can be captured, so the exact content and credential‑capture mechanisms remain unknown. Defenders should continue to block the IP address 188.114.96.3, add the fully qualified domain to endpoint and web‑gateway blocklists, and monitor other Typedream‑generated subdomains for similar patterns. Because the site currently returns a server error, active probing is unlikely to yield additional payloads, yet threat‑intel feeds should be updated to reflect the confirmed brand‑impersonation status and the presence of the domain on existing blocklists. Ongoing vigilance is recommended to detect re‑registration attempts or derivative domains that reuse the same hosting provider or SSL profile.
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
사이트 구성 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.