bitbuii[.]pages[.]dev
“Exodus Web3 Wallet Dashboard | Track & Manage Your Portfolio”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
On July 24, 2026 analysts observed that the domain bitbuii.pages.dev is currently offline but exhibits multiple indicators of a brand‑impersonation campaign targeting the Ethereum ecosystem. The site was registered on March 03 2026 through Cloudflare, Inc., and its authoritative nameservers are fish.ns.cloudflare.com and stan.ns.cloudflare.com. DNS resolution points to IP 172.66.44.60, an address owned by AS13335 Cloudflare, Inc. and located in the United States. The TLS certificate presented is issued by Google Trust Services under the “WE1” designation, confirming a valid HTTPS endpoint. HTTP probing returned a 403 status code, and the server advertises HSTS and HTTP/3 support, consistent with Cloudflare’s edge configuration.
Content inspection revealed the page title “Exodus Web3 Wallet Dashboard | Track & Manage Your Portfolio,” which aligns with a legitimate Exodus wallet interface but does not directly reference Ethereum. Nevertheless, the intelligence categorises the domain as impersonating the Ethereum brand. VirusTotal analysis recorded four detections out of ninety‑four scanned security vendors, indicating that a minority of scanners have flagged the domain as malicious. Independent blocklist monitoring shows the domain listed on three security blocklists, and it is actively blocked by PhishDestroy, MetaMask, and SEAL. The Gridinsoft trust score is zero out of one hundred, reinforcing the low trust assessment.
Because the site is presently taken offline, real‑time interaction data are limited. The absence of additional forensic artifacts, such as captured login forms or malicious payloads, leaves the exact attack vector uncertain. Defenders should continue to block the domain at network perimeter and DNS layers, update threat‑intel feeds with the observed indicators, and monitor for any re‑hosting attempts that reuse the same domain name, IP range, or TLS certificate fingerprint.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of bitbuii.pages.dev · checked Mar 4, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo