usa-exdosweb3[.]pages[.]dev
“Exodus Web3 Wallet — Secure Crypto & NFT Access”
已存储的观测记录
观测到的标题差异
证据摘要
This domain, usa-exdosweb3.pages.dev, is identified as a high-risk brand impersonation threat targeting cryptocurrency users under the guise of the Exodus Web3 Wallet. The site presents itself as a portal for secure crypto and NFT access, a common tactic to deceive users into interacting with malicious smart contracts or disclosing private keys. Analysis of the page title, "Exodus Web3 Wallet — Secure Crypto & NFT Access," confirms the intent to impersonate a legitimate cryptocurrency wallet provider, likely to facilitate unauthorized transactions or deploy crypto drainer scripts. Technical indicators reveal the domain was flagged by 13 out of 95 security vendors on VirusTotal, a relatively high detection rate for a newly observed threat. It is registered through Cloudflare, Inc., and resolves to the IP address 172.66.47.7. The domain was created on March 03, 2026, though this date may reflect spoofed registration metadata or a placeholder. It appears on three security blocklists and is actively blocked by at least three major security providers. The SSL certificate is issued by Google Trust Services, and the site employs HSTS and HTTP/3, likely to enhance the appearance of legitimacy. No direct evidence of a specific drainer kit was observed, but the infrastructure aligns with known crypto phishing campaigns. As of the latest verification, the domain has been taken offline, reducing immediate exposure to end users. However, the underlying infrastructure remains a residual risk. The use of Cloudflare’s hosting and CDN services, combined with a valid SSL certificate, suggests the threat actor may redeploy similar domains or reuse the same hosting provider for future campaigns. Users who interacted with this domain prior to its takedown should assume credential or private key compromise and take immediate action, including revoking active sessions, transferring assets to new wallets, and monitoring for unauthorized transactions. Security teams should monitor for related domains using the same hosting provider or SSL certificate issuer to preemptively block emerging threats.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of usa-exdosweb3.pages.dev · checked Jun 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控