EN ES PT
Back to Stats

Visual Capture

Screenshot of home-web3-exodus.pages.dev

Detection Info

http://home-web3-exodus.pages.dev
Detected Brand
Exodus Wallet
Country
International
Confidence
100%
HTTP Status
200
Report ID
7200d3d0-11fโ€ฆ
Analyzed
2026-02-06 15:00
Final URL (after redirects)
https://home-web3-exodus.pages.dev/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14042D73AF344137A41874ABAF34227F5A37C8959E3035FA9B5BAC04823BAD1546B37C5
CONTENT ssdeep
384:1RYk5bUoebYaJpRekiJRGB7hmlzzatTZL6q:/Naze7RGBsl3uN

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
d6633c2d9a329678
VISUAL aHash
3c3c3c3c3c3c3c3c
VISUAL dHash
f0ccccccccd4d4e4
VISUAL wHash
3c3c3c3c3c3c3c3c
VISUAL colorHash
030000001c0
VISUAL cropResistant
7a78676666666a6a,929292db92929292,8280922bcad2a28a,f0ccccccccd4d4e4

Code Analysis

Risk Score 76/100
Threat Level ALTO
โš ๏ธ Phishing Confirmed
๐ŸŽฃ Credential Harvester ๐ŸŽฃ OTP Stealer ๐ŸŽฃ Banking ๐ŸŽฃ Personal Info

๐Ÿ”ฌ Threat Analysis Report

โ€ข Threat: Phishing
โ€ข Target: Exodus Wallet users
โ€ข Method: Impersonation through a look-alike website.
โ€ข Exfil: Unknown, but likely targets private keys.
โ€ข Indicators: Free hosting and brand logo on a phishing domain.
โ€ข Risk: HIGH

๐Ÿ”’ Obfuscation Detected

  • fromCharCode
  • unicode_escape

๐ŸŽฏ Kit Endpoints

  • https://evilmartians.com/chronicles/postcss-8-plugin-migration`),m.env.LANG&&m.env.LANG.startsWith(
  • https://tailwindcss.com/docs/content-configuration#safelisting-classes
  • https://tailwindcss.com`}),...e.nodes])},container:(()=
  • https://tailwindcss.com/docs/content-configuration
  • https://mths.be/cssesc
  • https://tailwindcss.com/docs/content-configuration#discarding-classes
  • https://tailwindcss.com/docs/upgrade-guide#prefix-cannot-be-a-function
  • https://tailwindcss.com/docs/upgrade-guide#configure-content-sources
  • https://tailwindcss.com/docs/using-with-preprocessors#nesting
  • https://cdn.tailwindcss.com
  • https://tailwindcss.com/docs/upgrade-guide#remove-dark-mode-configuration
  • https://www.w3ctech.com/topic/2226`));let
  • https://tailwindcss.com/docs/content-configuration#pattern-recommendations
  • https://twitter.com/browserslist
  • https://tailwindcss.com/docs/upgrade-guide#replace-variants-with-layer
  • https://tailwindcss.com/docs/installation

๐Ÿ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Free Hosting with Brand Logo
The combination of free hosting and the presence of the Exodus logo is a strong indicator of phishing.
Impersonation
The site attempts to replicate the official brand.

๐Ÿ”ฌ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Exodus Wallet users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

โš ๏ธ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 18 obfuscation techniques

๐Ÿข Brand Impersonation Analysis

Impersonated Brand
Exodus Wallet
Official Website
https://www.exodus.com/
Fake Service
Exodus Wallet

โš”๏ธ Attack Methodology

Primary Method: Credential Harvesting

The attacker likely wants to trick users into providing their seed phrases or other sensitive information, which would allow them to gain access to their Exodus wallets and steal their funds.

๐ŸŒ Infrastructure Indicators of Compromise

๐Ÿฆ  Malicious Files

Main File
cdn.tailwindcss.com
File Size

๐Ÿ”ฌ JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
397.7ย KB

๐Ÿ”— API Endpoints Detected

Other
5

๐Ÿ” Obfuscation Detected

  • : Moderate

๐Ÿค– AI-Extracted Threat Intelligence

๐ŸŽฏ Malicious Files Identified

Main Drainer
cdn.tailwindcss.com
File Size
397KB

Scan History for home-web3-exodus.pages.dev

Found 1 other scan for this domain

๐Ÿ˜ฐ
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.