MALICIOUS — CRITICAL
exodssweb[.]pages[.]dev
On 24 July 2026, exodssweb.pages.dev was observed serving a HTTP 403 response and is currently taken offline.
- VirusTotal
- 2/93
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilidade
- Acessível · acesso restrito · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
exodssweb.pages.dev — Acessível · acesso restrito (HTTP 403). Representação da marca: Across; Tipo de golpe: Seed Phrase Theft. Resumo das evidências: VirusTotal 2/93 (ChainPatrol, Phishing Database); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 85/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
On 24 July 2026, exodssweb.pages.dev was observed serving a HTTP 403 response and is currently taken offline. The domain was registered on 27 February 2026 through Cloudflare, Inc. and resolves to the IP address 172.66.44.209, which belongs to AS13335 (Cloudflare) and is geolocated in the United States. DNS resolution uses the Cloudflare‑provided nameservers adi.ns.cloudflare.com, karl.ns.cloudflare.com, norman.ns.cloudflare.com, and paris.ns.c. The site presented the page title “Exodus® Web3 Wallet | Exodus® Browser Extension — Presentation,” indicating a wallet/seed phishing attempt that targets the Exodus brand, although the provided intelligence lists the brand target as “across.” SSL is delivered by Google Trust Services under the WE1 certificate, and the connection enforces HSTS while supporting HTTP/3, typical of Cloudflare‑protected services.
The Gridinsoft trust score is 0 / 100, and the domain appears on three external security blocklists. VirusTotal analysis shows that 2 of 93 scanning engines flagged the domain as malicious. Additional blocklist sources, including PhishDestroy, MetaMask, and SEAL, have already listed the domain. The evidence confirms a wallet/seed phishing infrastructure leveraging reputable hosting and SSL to increase credibility.
While the site is presently offline, defenders should continue to block the domain at perimeter and DNS layers, monitor the IP address 172.66.44.209 for any future activity, and add the associated nameservers to watchlists. Because the page content has not been captured, the exact phishing payload remains unknown; threat‑intel teams should consider periodic re‑scans in case the site resurfaces. Organizations that use Exodus wallets or related Web3 extensions should alert users to the potential credential‑harvesting attempt and enforce multi‑factor authentication where possible.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of exodssweb.pages.dev · checked Apr 12, 2026
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.