Analysis of exudosdfsd3walet.webflow.io as of July 28, 2026 indicates that the domain is actively being used for phishing. VirusTotal reports that 15 of 91 security vendors have flagged the domain, demonstrating a moderate consensus of malicious classification. The domain is registered through Webflow, Inc., a legitimate site‑building service, and the nameserver information is unavailable (NS_NOT_FOUND). Infrastructure inspection shows the domain resolving to the IP address 172.64.151.8, which is hosted on the same network used by other Webflow‑based sites. The domain appears on two reputable phishing blocklists, PhishDestroy and OpenPhish, confirming that external threat‑intelligence feeds have identified it as malicious.
No additional evidence such as SSL certificate details, HTTP response codes, page title, or content analysis is currently available, leaving the exact phishing vector and targeted brand unspecified. The lack of visible page metadata means that automated content‑based detection cannot be applied at this time. Defenders should prioritize blocking traffic to both the domain and its resolved IP address at perimeter firewalls and DNS filtering solutions. Adding the domain to internal blocklists and ensuring that existing phishing‑specific feeds (including PhishDestroy and OpenPhish) are actively consumed will reduce exposure.
Continuous monitoring of outbound connections to 172.64.151.8 is advised, as the IP could be reused for additional malicious campaigns. Because the registrar is a well‑known provider, takedown requests may be less effective; however, reporting the malicious use to Webflow’s abuse team could result in service termination. Organizations should also educate users about unsolicited communications that may reference this domain, emphasizing verification of URLs before credential entry. Until further forensic analysis of the hosted content is performed, the domain should be treated as high‑risk and fully blocked.