download-exodus[.]io
“Exodus Wallet: Download the world's leading bitcoin and crypto wallet”
download-exodus.io — Неперевірений. Уособлення бренду: Exodus; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLScan malicious verdict; Google Safe Browsing flagged; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Hosting Concepts.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, download-exodus.io, is a confirmed phishing infrastructure designed to impersonate the Exodus cryptocurrency wallet. Analysis indicates the site presents itself as the official Exodus download portal, using the page title 'Exodus Wallet: Download the world's leading bitcoin and crypto wallet' to deceive users into downloading malicious software or disclosing sensitive credentials. The threat specifically targets cryptocurrency holders by mimicking legitimate wallet distribution channels, potentially leading to unauthorized access to digital assets or installation of malware designed to exfiltrate private keys and recovery phrases. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on November 5, 2025, through Hosting Concepts B.V. d/b/a Registrar.eu, and resolves to the IP address 45.82.82.240 located in Russia (AS9123 JSC TIMEWEB). Security vendors have flagged the domain in 21 out of 95 VirusTotal scans, while it appears on four distinct security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. Google Safe Browsing has also classified the domain as phishing, and no valid SSL certificate was detected, further reducing its legitimacy. The combination of these technical indicators confirms the domain's role in active brand impersonation campaigns. Users who visited download-exodus.io should immediately cease all interaction with the site and any downloaded files. If credentials or recovery phrases were entered, affected wallets should be considered compromised, and funds should be transferred to a new, secure wallet using a clean device. Devices used to access the domain should undergo a full malware scan using updated security tools. Additionally, users should monitor their cryptocurrency transactions for unauthorized activity and enable multi-factor authentication on all related accounts. Given the domain's current offline status, no further direct threat is posed, but vigilance is advised for similar impersonation attempts.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога