MALICIOUS — HIGH
en-web--exod[.]pages[.]dev
This domain, en-web--exod.pages.dev, is identified as a credential harvesting phishing site designed to mimic legitimate authentication portals.
- VirusTotal
- 2/94
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Доступно · доступ обмежено · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
en-web--exod.pages.dev — Доступно · доступ обмежено (HTTP 403). Уособлення бренду: Genericcloudflare; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 2/94 (ChainPatrol, Phishing Database); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This domain, en-web--exod.pages.dev, is identified as a credential harvesting phishing site designed to mimic legitimate authentication portals. Analysis indicates the infrastructure was engineered to capture user login credentials, likely targeting financial or cryptocurrency service accounts given its association with known threat blocklists and detection patterns. The site employed deceptive login interfaces to trick users into submitting sensitive information, which could then be exploited for unauthorized access or fraudulent transactions. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. and resolved to the IP address 172.66.47.62. It was created on March 04, 2026, and subsequently flagged by 10 out of 95 security vendors on VirusTotal. The domain appeared on three distinct security blocklists and was actively blocked by multiple threat intelligence platforms. The SSL certificate was issued by Google Trust Services, a common tactic used to lend an appearance of legitimacy to malicious sites. The page title, 'Suspected phishing site | Cloudflare,' further corroborates its fraudulent nature, as this is a default warning applied by Cloudflare to flagged content. Users who visited en-web--exod.pages.dev should immediately revoke any credentials entered on the site, particularly if they were reused across other platforms. Monitor accounts associated with the submitted credentials for unauthorized activity, such as login attempts or transactions. If financial or cryptocurrency services were targeted, enable multi-factor authentication and review recent account changes. Given the domain's presence on multiple blocklists, affected users should also scan their devices for additional malware or unauthorized access points. Report the incident to relevant security teams or fraud prevention units to aid in broader mitigation efforts.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of en-web--exod.pages.dev · checked Jun 26, 2026
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.