en-exodua-io-web[.]pages[.]dev
“Exodus Web3 Wallet — Securely Manage, Swap & Explore”
en-exodua-io-web.pages.dev — Контент недоступний. Уособлення бренду: Across; Тип шахрайства: Seed Phrase Theft. Зведення доказів: VirusTotal 2/94 (ChainPatrol, Trustwave); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
en-exodua-io-web.pages.dev was observed hosting a page titled “Exodus Web3 Wallet — Securely Manage, Swap & Explore”. The title directly references the Exodus Web3 Wallet brand, indicating an attempt to impersonate the legitimate service. The domain was registered through Cloudflare on 2026-03-06 and resolves to the Cloudflare‑owned address 188.114.97.3, which belongs to ASN 13335 (Cloudflare, Inc.) and is physically located in the United States. TLS termination is provided by Google Trust Services under the WE1 certificate, and the site enforced HSTS and HTTP/3, consistent with typical Cloudflare configurations.
Security telemetry shows the domain appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL, and is classified as a wallet/seed phishing campaign. VirusTotal recorded detections from 2 of 94 scanning engines, confirming that at least a minority of AV products flag the host as malicious. The Gridinsoft trust score is 0 out of 100, reinforcing the malicious assessment. An HTTP request returned a 403 status code, suggesting that the server is currently denying access, which aligns with the reported offline status.
Defenders should treat the domain as hostile and block any network communication to 188.114.97.3 when associated with the en-exodua-io-web.pages.dev hostname. Monitoring for newly created subdomains under the same registrar or similar naming patterns is advisable, given the recent creation date. Because the page content is not currently accessible, further behavioural analysis is limited; however, the combination of brand‑specific title, low trust score, blocklist presence, and partial AV detections provides sufficient evidence to classify the domain as a credential‑stealing threat targeting users of the Exodus Web3 Wallet. Organizations should educate users about the risk of entering seed phrases on untrusted sites and enforce policies that restrict access to known wallet domains.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of en-exodua-io-web.pages.dev · checked Apr 12, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога