ur-exoduse[.]pages[.]dev
Проверка домена ur-exoduse.pages.dev на фишинг и безопасность
“Suspected phishing site | Cloudflare”
ur-exoduse.pages.dev — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Exodus; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 7/93 (ChainPatrol, alphaMountain.ai, CyRadar, ESET, Fortinet); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain ur-exoduse.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and resolves to IP address 172.66.44.240, an endpoint owned by AS13335 Cloudflare, Inc. in the United States. The site served a HTTP 403 response and presented the page title "Suspected phishing site | Cloudflare". TLS termination is performed by a Google Trust Services certificate (WE1), indicating a valid, publicly trusted HTTPS configuration. Detected infrastructure components include HTTP/3 support and enforced HSTS, both provisioned by Cloudflare.
The authoritative name servers listed are adi.ns.cloudflare.com, arturo.ns.cloudflare.com, karl.ns.cloudflare.com, and laura.ns.cloudflare.com, confirming Cloudflare’s hosting role. The domain is explicitly associated with brand impersonation of the cryptocurrency wallet provider Exodus and is classified as a crypto‑scam vector. Gridinsoft assigned a trust score of 0 out of 100, and the domain is presently offline. Threat intelligence platforms have blocked the domain via PhishDestroy, MetaMask, and SEAL, and it appears on three external security blocklists.
VirusTotal analysis shows that seven of ninety‑three scanning engines flagged the domain, reinforcing its malicious disposition. While the page title and blocklist presence substantiate the impersonation claim, no additional content analysis is available because the site is offline, leaving the exact phishing or credential‑harvesting mechanisms unverified. Defenders should continue to block the IP address 172.66.44.240, add the domain to internal deny lists, monitor for re‑registration or new subdomains under the same registrar, and incorporate the observed indicators—creation date, SSL issuer, Cloudflare name servers, and blocklist references—into brand‑protection and threat‑intel feeds to pre‑empt future exploitation of the Exodus brand.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of ur-exoduse.pages.dev · checked Apr 11, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание