MALICIOUS — CRITICAL
doc-exod-s[.]pages[.]dev
4 of 94 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 403.
- VirusTotal
- 4/94
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Доступен · доступ ограничен · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
doc-exod-s.pages.dev — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Binance; Тип мошенничества: Crypto Drainer. Сводка доказательств: VirusTotal 4/94 (ADMINUSLabs, ChainPatrol, Kaspersky, Phishing Database); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Digest
doc-exod-s.pages.dev is classified critical with an evidence score of 80/100. 4 of 94 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 12 Mar 2026 via Cloudflare, Inc., hosted on 172.66.44.114 (CLOUDFLARENET - Cloudflare, Inc., US, US). The latest stored check on 9 Aug 2026 returned HTTP 403 and includes a capture.
Stored generated summary (templated)cerebras · 25.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of the domain doc-exod-s.pages.dev, observed on July 25 2026, shows a clear brand impersonation attempt aimed at Binance users. The site returned an HTTP 403 status code and presented the page title "Getting Started with Exódus® Web3 Wallet — Exódus® Browser," which aligns with the declared scam type of wallet/seed phishing. Infrastructure inspection reveals the domain resolves to IP address 172.66.44.114, hosted within the United States under ASN 13335 owned by Cloudflare, Inc. The SSL certificate is issued by Google Trust Services under the WE1 identifier, and the domain is served through Cloudflare with HSTS and HTTP/3 enabled, indicating a modern web stack. Registration data shows the domain was created on March 12 2026 and was registered via Cloudflare, Inc., using the nameservers kallie.ns.cloudflare.com and vicky.ns.cloudflare.com.
Threat intelligence indicates that three security blocklists have already listed the domain, and it is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis recorded four detections out of ninety‑four scanning engines, reinforcing the malicious classification. The Gridinsoft trust score of 0 out of 100 further confirms a low reputation. While the site is currently offline, the observed indicators suggest a coordinated effort to harvest cryptocurrency wallet credentials.
Uncertainties remain regarding the exact content served before takedown and any additional infrastructure used for credential exfiltration. Defenders should immediately add doc-exod-s.pages.dev to DNS and URL filtering policies, monitor for similarly named subdomains, and enforce strict wallet address verification controls for Binance‑related transactions. Continuous monitoring of Cloudflare‑hosted domains that reference the Exódus brand is recommended to detect future impersonation attempts.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of doc-exod-s.pages.dev · checked Mar 12, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.