MALICIOUS — CRITICAL
exxodus--web[.]pages[.]dev
Analysis of exxodus--web.pages.dev, observed as a credential‑phishing site, shows that the domain was registered on September 18 2025 through Cloudflare, Inc.
- VirusTotal
- 13/94
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Доступен · доступ ограничен · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
exxodus--web.pages.dev — Доступен · доступ ограничен (HTTP 403). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 13/94 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 94/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
Analysis of exxodus--web.pages.dev, observed as a credential‑phishing site, shows that the domain was registered on September 18 2025 through Cloudflare, Inc. The authoritative nameservers are nucum.ns.cloudflare.com and sage.ns.cloudflare.com, both belonging to Cloudflare’s DNS infrastructure. DNS resolution points to the IP address 172.66.44.212, which is announced by AS13335, the Cloudflare network, and geolocated to the United States. The TLS certificate presented is issued by Google Trust Services, confirming the use of a legitimate, publicly trusted certificate chain. HTTP responses return a 403 status code, and the server advertises HSTS and HTTP/3, indicating a modern Cloudflare edge configuration.
Reputation data is strongly negative: Gridinsoft assigns a trust score of 0 / 100, and the domain appears on three independent security blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis reports that 13 of 94 scanning engines have flagged the domain, reinforcing the malicious assessment. The page title returned by the server is identical to the domain name, providing no additional context.
The primary threat classification is credential phishing, though the specific targeted service or brand is not disclosed in the collected metadata. The site is currently taken offline, which limits real‑time observation but does not remove the historical risk. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑registration or re‑use of the same IP space, and update detection signatures to incorporate the observed HSTS/HTTP‑3 fingerprint and the Cloudflare‑issued certificate details. Additional investigation may be required to locate any associated phishing landing pages or payloads that were previously hosted under this domain.
Охват данных12 recorded checks
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of exxodus--web.pages.dev · checked Mar 16, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.