MALICIOUS — CRITICAL
exo-dsus-doc.pages.dev — Crypto Wallet Drainer Phishing Report
exo-dsus-doc[.]
This domain, exo-dsus-doc.pages.dev, is identified as a crypto wallet drainer phishing site designed to steal digital assets from unsuspecting users.
- VirusTotal
- 7/94
- Blocklists
- 2 · MetaMask, SEAL
- Kullanılabilirlik
- Ulaşılabilir · erişim kısıtlı · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
exo-dsus-doc.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Genericcloudflare; Dolandırıcılık türü: Crypto Drainer. Kanıt özeti: VirusTotal 7/94 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, CyRadar); URLQuery 1 alert; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 76/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
This domain, exo-dsus-doc.pages.dev, is identified as a crypto wallet drainer phishing site designed to steal digital assets from unsuspecting users. The infrastructure mimics legitimate wallet interfaces to trick visitors into entering private keys or seed phrases, which are then harvested to siphon funds from connected cryptocurrency wallets. Analysis indicates the site employs evasion techniques, including Cloudflare hosting and HTTP/3, to obscure its malicious intent and delay detection by security tools. Infrastructure analysis reveals the domain was registered on October 13, 2025, through Cloudflare, Inc., a provider frequently leveraged by threat actors to conceal hosting origins. The site resolves to the IP address 172.66.47.197 and is flagged by 5 out of 95 security vendors on VirusTotal, including MetaMask and PhishDestroy. Additional indicators include a Gridinsoft trust score of 0/100 and presence on three security blocklists, confirming its malicious classification. The SSL certificate, issued by Google Trust Services, further suggests an attempt to appear legitimate while facilitating credential theft. Users who visited exo-dsus-doc.pages.dev or entered sensitive information should immediately disconnect the device from the internet and revoke access to any connected cryptocurrency wallets. Transfer remaining assets to a new wallet with a fresh seed phrase, and monitor all linked accounts for unauthorized transactions. Report the incident to relevant wallet providers and consider filing a report with local cybercrime authorities. Avoid reusing passwords or seed phrases from compromised sessions, and verify future interactions with wallet interfaces through official channels only.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | exo-dsus-doc.pages.dev |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of exo-dsus-doc.pages.dev · checked Jun 26, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.