exo-ds-web[.]pages[.]dev
“Exodus Wallet | Secure Cryptocurrency Wallet for Desktop & Mobile”
exo-ds-web.pages.dev — Доступно · доступ обмежено (HTTP 403). Уособлення бренду: Ethereum; Тип шахрайства: Seed Phrase Theft. Зведення доказів: VirusTotal 2/94 (ChainPatrol, Phishing Database); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of exo-ds-web.pages.dev indicates this domain was a short-lived phishing site impersonating Exodus Wallet, a cryptocurrency wallet service. The domain was registered on March 6, 2026, through Cloudflare, Inc., and resolved to IP 172.66.44.159, hosted on Cloudflare's network (AS13335) in the United States. The page title, 'Exodus Wallet | Secure Cryptocurrency Wallet for Desktop & Mobile,' directly mimics the branding of the legitimate Exodus service, aligning with the reported scam type of wallet/seed phishing. At the time of assessment, the domain appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL.
Two of 94 security vendors on VirusTotal flagged the domain as malicious. The domain's SSL certificate is issued by Google Trust Services (WE1), a common certificate authority used by both legitimate and malicious sites. The HTTP status returned a 403 error, suggesting the site may have been taken offline or restricted by the hosting provider. Infrastructure analysis reveals the use of Cloudflare nameservers (collins.ns.cloudflare.com and gannon.ns.cloudflare.com) and technologies such as HSTS and HTTP/3, which are consistent with modern web hosting but do not inherently indicate malicious intent.
The Gridinsoft trust score of 0/100 further corroborates the domain's classification as high-risk. Defenders should treat this domain as confirmed malicious, particularly in environments involving cryptocurrency transactions. While the domain is currently offline, historical DNS and WHOIS records should be preserved for forensic analysis. No evidence suggests this domain is part of a broader campaign, but defenders are advised to monitor for similar patterns involving Cloudflare-hosted pages impersonating cryptocurrency services.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of exo-ds-web.pages.dev · checked Apr 12, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога