us--exxodus-web[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
The domain us--exxodus-web.pages.dev was observed hosting a page whose title reads "Suspected phishing site | Cloudflare". The site resolved to the IP address 172.66.47.156, which is owned by Cloudflare, Inc. (AS13335) and is geolocated to the United States. Cloudflare’s DNS records show the authoritative nameservers lia.ns.cloudflare.com and ram.ns.cloudflare.com, confirming that the domain is fully provisioned through Cloudflare’s platform. Technical fingerprints indicate the presence of HTTP/3 and enforced HTTP Strict Transport Security (HSTS), both standard Cloudflare features. Security telemetry flags the domain as high‑risk.
The Gridinsoft trust score is 0 out of 100, indicating a lack of trust. Fifteen of ninety‑four VirusTotal scanners have flagged the domain, and the site appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL. The HTTP response returned a 403 status code before the site was taken offline, suggesting that access was blocked or the content was removed. The current status is listed as offline, and the domain is no longer reachable. Evidence does not reveal the specific phishing kit or targeted brand beyond the generic page title.
No additional intelligence such as OTX identifiers, Safe Browsing alerts, or detailed payload analysis is available. Consequently, the precise lure or victim profile remains uncertain. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any re‑registration or new sub‑domains under the same parent zone, and update endpoint protection signatures to include the observed VirusTotal detections. Given the Cloudflare hosting, any future re‑hosting is likely to retain the same IP range, so IP‑based allow‑list rules should be reviewed. Continuous observation of the domain’s registration status is recommended, as the registrar information shows the domain was registered through Cloudflare, Inc., which may facilitate rapid redeployment.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | us--exxodus-web.pages.dev |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
8 внешних источников под наблюдением Совпадений нет
Технологии
Выявлено 3 технологии с высокой уверенностью
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of us--exxodus-web.pages.dev · checked Mar 16, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание