exxodus--web[.]pages[.]dev
Перевірка домену exxodus--web.pages.dev на фішинг і безпеку
“exxodus--web.pages.dev”
exxodus--web.pages.dev — Доступно · доступ обмежено (HTTP 403). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 13/94 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 94/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of exxodus--web.pages.dev, observed as a credential‑phishing site, shows that the domain was registered on September 18 2025 through Cloudflare, Inc. The authoritative nameservers are nucum.ns.cloudflare.com and sage.ns.cloudflare.com, both belonging to Cloudflare’s DNS infrastructure. DNS resolution points to the IP address 172.66.44.212, which is announced by AS13335, the Cloudflare network, and geolocated to the United States. The TLS certificate presented is issued by Google Trust Services, confirming the use of a legitimate, publicly trusted certificate chain. HTTP responses return a 403 status code, and the server advertises HSTS and HTTP/3, indicating a modern Cloudflare edge configuration.
Reputation data is strongly negative: Gridinsoft assigns a trust score of 0 / 100, and the domain appears on three independent security blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis reports that 13 of 94 scanning engines have flagged the domain, reinforcing the malicious assessment. The page title returned by the server is identical to the domain name, providing no additional context.
The primary threat classification is credential phishing, though the specific targeted service or brand is not disclosed in the collected metadata. The site is currently taken offline, which limits real‑time observation but does not remove the historical risk. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑registration or re‑use of the same IP space, and update detection signatures to incorporate the observed HSTS/HTTP‑3 fingerprint and the Cloudflare‑issued certificate details. Additional investigation may be required to locate any associated phishing landing pages or payloads that were previously hosted under this domain.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of exxodus--web.pages.dev · checked Mar 16, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога