portal-en-exdua-web[.]pages[.]dev
“Exodus Wallet - Secure Multi-Asset Cryptocurrency Wallet”
portal-en-exdua-web.pages.dev — Контент недоступний. Уособлення бренду: Across; Тип шахрайства: Seed Phrase Theft. Зведення доказів: VirusTotal 7/94 (ADMINUSLabs, ChainPatrol, CyRadar, Fortinet, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of portal-en-exdua-web.pages.dev (seed de9d71) indicates that the domain was registered on March 6, 2026 through Cloudflare, Inc. and is hosted on the Cloudflare network (ASN 13335) with the IP address 172.66.44.98 located in the United States. The authoritative name servers chan.ns.cloudflare.com and norman.ns.cloudflare.com resolve to the same infrastructure, confirming that the operator leveraged Cloudflare’s DNS and CDN services. The site presents the page title “Exodus Wallet – Secure Multi-Asset Cryptocurrency Wallet”, and the declared scam type is Wallet/Seed Phishing, targeting users of cryptocurrency wallets. The brand target is listed as “across”, indicating a broad impersonation attempt rather than a single brand.
The domain is currently offline, returning an HTTP 403 status code, and is listed on three security blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL, reflecting consensus among anti-phishing products that the domain is malicious. VirusTotal analysis shows that seven of ninety-four scanners flagged the domain, reinforcing the detection consensus. The SSL certificate is issued by Google Trust Services under the WE1 hierarchy, which is typical for Cloudflare‑issued certificates and does not provide a trust advantage for the malicious actor.
A Gridinsoft trust score of 0 out of 100 further emphasizes the high risk associated with the site. Defenders encountering traffic to this domain should block the resolved IP address 172.66.44.98 and the full hostname, update web filtering rules to include the three identified blocklists, and enforce client‑side warnings for any content that claims to be an Exodus wallet login page. Continuous monitoring of Cloudflare‑originated domains is advised, as the service can be abused for short‑lived phishing infrastructure. Because the site is already offline, immediate incident response may focus on containment of any credential harvesting that could have occurred before takedown.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of portal-en-exdua-web.pages.dev · checked Mar 26, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога