welcome--exodus[.]dora[.]run
“Exódus® Web3 Wallet | Exodus® Browser Exténsion”
welcome--exodus.dora.run — Контент недоступний (HTTP 502). Уособлення бренду: Exodus Wallet; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 11 detections (engine total unavailable) (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: Alibaba Cloud Computing.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain welcome--exodus.dora.run is a high-risk brand impersonation phishing website targeting Exodus Wallet users. It poses as the legitimate Exodus Web3 Wallet and browser extension, using a deceptive page title 'Exódus® Web3 Wallet | Exodus® Browser Exténsion' to trick visitors into entering sensitive information. The site is now taken offline, but it was a cryptocurrency scam designed to steal credentials or funds. This domain is not safe and should be avoided.
Technical indicators confirm the threat: VirusTotal shows 11 of 95 security vendors flagging the domain, including ADMINUSLabs, ChainPatrol, and alphaMountain.ai. Google Safe Browsing did not flag it, but it appears on 3 security blocklists: PhishDestroy, MetaMask, and SEAL. The domain was registered through Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn) on 2026-02-21 07:01:08, resolves to IP address 52.223.42.255 (US, AS16509 Amazon.com, Inc.), and uses an SSL certificate issued by Amazon / Amazon RSA 2048 M03. The site returned an HTTP 404 status when last checked, and technologies detected include Amazon Web Services and AWS Certificate Manager.
Users who interacted with welcome--exodus.dora.run should take immediate safety steps. Since this is a crypto drainer or credential phishing site, revoke any token approvals given to the site and move funds to a new wallet. Change passwords for any accounts used on the site and enable two-factor authentication (2FA) on all cryptocurrency-related services. Monitor accounts for unauthorized transactions and report the domain to Exodus Wallet support, as well as to security platforms like PhishDestroy and MetaMask for continued blocking.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: dora.run
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain dora.run behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Cloud computing platform offering compute, storage, and networking services.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога