regist-exodus[.]com
“Exodus: the world's leading bitcoin and crypto wallet”
Сводка доказательств
The domain regist-exodus.com was registered on February 21, 2026 and is currently reported as taken offline. Technical analysis shows that it resolves to the IPv6 address 2606:4700:4408::6812:24d4, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The site presented the page title "Exodus: the world's leading bitcoin and crypto wallet," directly referencing the Exodus brand, indicating a clear case of brand impersonation aimed at cryptocurrency users. The domain appears on three security blocklists—PhishDestroy, MetaMask, and SEAL—demonstrating that multiple threat‑intelligence providers have identified it as malicious.
VirusTotal scans recorded two detections out of ninety‑three participating security vendors, providing additional confirmation of its suspicious nature. The SSL certificate associated with the domain is identified as WE1, though no further certificate details are available. While the site is presently offline, the existing indicators suggest it was used for a crypto‑related scam, likely to harvest credentials or lure victims into fraudulent transactions.
Uncertainties remain regarding the exact payload, the specific phishing page layout, and whether any additional infrastructure was employed. Defenders should continue to block regist-exodus.com at network perimeters, update URL filtering and DNS threat‑intel feeds with the observed indicators, and monitor for new domains that reuse the same brand name or similar IP ranges. Ongoing observation of Cloudflare‑hosted IPv6 addresses linked to this activity is recommended to detect any re‑activation or migration of the campaign.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.exodus.com/_next/static/chunks/80507811.7cd4545731387f40.js?dpl=dpl_8ffzu8ta94flpgl8xudhhbab1yar |
audit | Hunting_JS_WebAssembly |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание