regist-exodus[.]com
“Exodus: the world's leading bitcoin and crypto wallet”
Kanıt özeti
The domain regist-exodus.com was registered on February 21, 2026 and is currently reported as taken offline. Technical analysis shows that it resolves to the IPv6 address 2606:4700:4408::6812:24d4, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The site presented the page title "Exodus: the world's leading bitcoin and crypto wallet," directly referencing the Exodus brand, indicating a clear case of brand impersonation aimed at cryptocurrency users. The domain appears on three security blocklists—PhishDestroy, MetaMask, and SEAL—demonstrating that multiple threat‑intelligence providers have identified it as malicious.
VirusTotal scans recorded two detections out of ninety‑three participating security vendors, providing additional confirmation of its suspicious nature. The SSL certificate associated with the domain is identified as WE1, though no further certificate details are available. While the site is presently offline, the existing indicators suggest it was used for a crypto‑related scam, likely to harvest credentials or lure victims into fraudulent transactions.
Uncertainties remain regarding the exact payload, the specific phishing page layout, and whether any additional infrastructure was employed. Defenders should continue to block regist-exodus.com at network perimeters, update URL filtering and DNS threat‑intel feeds with the observed indicators, and monitor for new domains that reuse the same brand name or similar IP ranges. Ongoing observation of Cloudflare‑hosted IPv6 addresses linked to this activity is recommended to detect any re‑activation or migration of the campaign.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.exodus.com/_next/static/chunks/80507811.7cd4545731387f40.js?dpl=dpl_8ffzu8ta94flpgl8xudhhbab1yar |
audit | Hunting_JS_WebAssembly |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin