exo-access-w-eb3[.]pages[.]dev
“Getting started with Exodus Web3 Wallet”
证据摘要
This domain, exo-access-w-eb3.pages.dev, is identified as a confirmed brand impersonation site targeting Exodus cryptocurrency wallet users. Analysis of the page title, 'Getting started with Exodus Web3 Wallet,' confirms the domain mimics legitimate Exodus wallet onboarding processes, likely designed to deceive users into disclosing recovery phrases or private keys. The infrastructure exhibits characteristics consistent with crypto drainer operations, where victims unknowingly authorize malicious transactions leading to unauthorized fund transfers. No specific drainer kit fingerprint has been conclusively attributed at this time, though the page structure aligns with known wallet impersonation templates. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc., resolving to the IP address 172.66.47.97, geolocated within the United States under AS13335 (Cloudflare, Inc.). The domain was created on September 19, 2025, and has since been flagged by 19 out of 95 security vendors on VirusTotal. It appears on three independent security blocklists, including entries from PhishDestroy, MetaMask, and SEAL. While Google Safe Browsing (GSB) status was not explicitly provided, the domain's presence on multiple blocklists suggests prior detection by major threat intelligence platforms. The use of Cloudflare Pages (.pages.dev) as a hosting mechanism is notable, as this service is frequently abused for rapid deployment of phishing infrastructure due to its low-cost, high-availability nature. As of the latest verification, exo-access-w-eb3.pages.dev has been taken offline, likely following abuse reports or automated takedown processes. However, the risk of reemergence remains high, as threat actors often redeploy similar infrastructure under new subdomains or altered naming conventions. Users who interacted with this domain should immediately revoke any connected wallet permissions, transfer remaining funds to a new wallet, and monitor transaction histories for unauthorized activity. Organizations maintaining crypto-related services are advised to preemptively block the domain and its resolved IP in perimeter defenses, while also monitoring for derivative domains incorporating 'exo,' 'access,' or 'web3' in combination with Cloudflare Pages infrastructure.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
技术
识别出 4 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of exo-access-w-eb3.pages.dev · checked Mar 16, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控