Is com-exodus-wallet.wasmer.app safe?
http://com-exodus-wallet.wasmer.app/
Fake Exodus wallet extension page flagged as phishing by 18 antivirus engines.
This page impersonates the Exodus crypto wallet to trick users into installing a fake browser extension. Eighteen of 92 antivirus engines flag it as malicious, with BitDefender and CyRadar specifically calling it phishing. Do not download or enter any wallet details.
Read the full analysis01 · Investigation Brief
Investigation Brief
The domain name mimics the legitimate Exodus wallet while hosting a page that promotes a browser extension download. Antivirus engines including BitDefender, CyRadar, and alphaMountain.ai flag the page as phishing or malicious. The captured content contains no contact details, no verifiable business information, and matches the tech-support-scam pattern. The hosting IP shows no abuse history, yet the page content and engine detections outweigh that single clean signal. The combination of impersonation, missing contact information, and widespread engine flags points to a credential-harvesting or malware-delivery operation.
Page Content
The captured page presents itself as an official guide for the Exodus Web3 Wallet browser extension. It offers step-by-step installation instructions and promises multi-chain support, NFT galleries, and hardware-wallet integration. No contact email, phone number, or physical address appears anywhere on the page. The text repeatedly urges visitors to download the extension from the Chrome Web Store or Brave, yet the domain itself is not the real exodus wallet site.
Infrastructure
The page is hosted on IP 5.78.31.66 with a clean abuse score and no prior reports. SSL is valid and issued by Let's Encrypt, expiring in 47 days. The single redirect hop stays within the same domain. Despite the clean hosting record, 18 of 92 antivirus engines still classify the URL as malicious.
Domain History
WHOIS data for the domain is unavailable; age, registrar, and owner details are unknown. The absence of any registration footprint is consistent with throw-away domains used in phishing campaigns.
Web Reputation
No independent review aggregators returned data for this host. The only reputation signals come from the antivirus detections themselves. BitDefender, CyRadar, Chong Lua Dao, ChainPatrol, alphaMountain.ai, and Ermes all flag the page.
What this means for you
Visiting the page risks downloading a fake wallet extension that could steal seed phrases or private keys. Do not click any download links or enter wallet credentials on this site.
Why the score is 14
The score combines saved deterministic evidence with the grounded analysis available for this report. Coverage remains separate so missing sources cannot be mistaken for clean results.
02 · Security Evidence
Security evidence
Antivirus Engines
Fresh result
19 engines flagged this URL
Every saved adverse engine is listed below. The full provider matrix remains available for audit.
- Malicious
- 18
- Suspicious
- 1
- Total
- 92
| Engine | Finding |
|---|---|
| alphaMountain.aiMalicious | malicious |
| BitDefenderMalicious | phishing |
| ChainPatrolMalicious | malicious |
| Chong Lua DaoMalicious | malicious |
| CyRadarMalicious | phishing |
| ErmesMalicious | phishing |
| ESETMalicious | phishing |
| Forcepoint ThreatSeekerMalicious | phishing |
| FortinetMalicious | phishing |
| G-DataMalicious | phishing |
| GridinsoftMalicious | phishing |
| KasperskyMalicious | phishing |
| LevelBlueMalicious | phishing |
| LionicMalicious | phishing |
| OpenPhishMalicious | phishing |
| RisingMalicious | phishing |
| SophosMalicious | phishing |
| VIPREMalicious | phishing |
| SOCRadarSuspicious | suspicious |
All 92 engine results
- alphaMountain.ai - malicious - Malicious
- BitDefender - phishing - Malicious
- ChainPatrol - malicious - Malicious
- Chong Lua Dao - malicious - Malicious
- CyRadar - phishing - Malicious
- Ermes - phishing - Malicious
- ESET - phishing - Malicious
- Forcepoint ThreatSeeker - phishing - Malicious
- Fortinet - phishing - Malicious
- G-Data - phishing - Malicious
- Gridinsoft - phishing - Malicious
- Kaspersky - phishing - Malicious
- LevelBlue - phishing - Malicious
- Lionic - phishing - Malicious
- OpenPhish - phishing - Malicious
- Rising - phishing - Malicious
- Sophos - phishing - Malicious
- VIPRE - phishing - Malicious
- SOCRadar - suspicious - Suspicious
- 0xSI_f33d - unrated - Clean
- Abusix - clean - Clean
- Acronis - clean - Clean
- ADMINUSLabs - clean - Clean
- AILabs (MONITORAPP) - clean - Clean
- AlienVault - clean - Clean
- AlphaSOC - unrated - Clean
- Antiy-AVL - clean - Clean
- ArcSight Threat Intelligence - unrated - Clean
- AutoShun - unrated - Clean
- Bfore.Ai PreCrime - unrated - Clean
- Bkav - unrated - Clean
- BlockList - clean - Clean
- Blueliv - clean - Clean
- Certego - clean - Clean
- CINS Army - clean - Clean
- Cluster25 - unrated - Clean
- CRDF - clean - Clean
- Criminal IP - unrated - Clean
- CSIS Security Group - unrated - Clean
- CTX AI - clean - Clean
- Cyan - unrated - Clean
- Cyble - clean - Clean
- desenmascara.me - clean - Clean
- DNS8 - unrated - Clean
- Dr.Web - clean - Clean
- EmergingThreats - clean - Clean
- Emsisoft - clean - Clean
- ESTsecurity - clean - Clean
- Fortra - unrated - Clean
- GCP Abuse Intelligence - unrated - Clean
- Google Safe Browsing - clean - Clean
- GreenSnow - clean - Clean
- GreyNoise - unrated - Clean
- Guardpot - unrated - Clean
- Heimdal Security - clean - Clean
- Hunt.io Intelligence - unrated - Clean
- IPsum - clean - Clean
- Juniper Networks - clean - Clean
- K7AntiVirus - unrated - Clean
- Lumu - unrated - Clean
- Malwared - clean - Clean
- MalwarePatrol - clean - Clean
- MalwareURL - unrated - Clean
- Mimecast - unrated - Clean
- Netcraft - unrated - Clean
- PhishFort - unrated - Clean
- Phishing Database - clean - Clean
- Phishtank - clean - Clean
- PREBYTES - clean - Clean
- PrecisionSec - unrated - Clean
- Quick Heal - clean - Clean
- Quttera - clean - Clean
- SafeToOpen - unrated - Clean
- Sangfor - clean - Clean
- Sansec eComscan - unrated - Clean
- Scantitan - clean - Clean
- SCUMWARE.org - clean - Clean
- Seclookup - clean - Clean
- Snort IP sample list - unrated - Clean
- StopForumSpam - clean - Clean
- Sucuri SiteCheck - clean - Clean
- ThreatHive - clean - Clean
- URLhaus - clean - Clean
- URLQuery - unrated - Clean
- Viettel Threat Intelligence - clean - Clean
- ViriBack - clean - Clean
- VX Vault - clean - Clean
- Webroot - clean - Clean
- Xcitium Verdict Cloud - clean - Clean
- Yandex Safebrowsing - clean - Clean
- ZeroCERT - clean - Clean
- ZeroFox - unrated - Clean
Security Scans
Checked against the browser threat feeds available to this scan — no hit.
03 · Investigation Story
Investigation story
- 1
What the site claims
Exodus Web3 Wallet | Getting Started with Exodus Browser Extension
- 2
What we observed
The page content was captured and checked alongside 92 antivirus results.
- 3
What independent research found
No complete independent-research result was available in this saved report.
- 4
What remains unverified
1 of the five core capabilities did not complete, so those gaps remain visible in the coverage ledger.
Wallet-drainer patterns detected
This page uses language and API references consistent with modern crypto wallet-drainer kits. If you connected your wallet or signed a transaction on this site, assume your wallet is compromised — revoke approvals, move funds to a fresh wallet with a new seed phrase, and treat the original as burned.
- ·Page asks for a wallet seed phrase / recovery phrase — legitimate wallets never do this.
Risk pattern correlation
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
04 · Domain & Infrastructure
Domain & infrastructure
The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Infrastructure map
How the saved page connected to the wider web.
Contact Verification
Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.
- No direct contact email found on the captured page.
- Scam family match: Tech-Support Scam.
Domain & Encryption
Redirect Chain
- 1308http://com-exodus-wallet.wasmer.app/
- 2206https://com-exodus-wallet.wasmer.app/
Server Reputation
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
05 · Evidence Ledger
Evidence ledger
The conclusion is supported by the evidence saved with this report.
Technical threat
Malware, phishing, credential theft and hostile infrastructure.
Wallet access request · Antivirus consensus
Operator / customer risk
Complaints, withdrawals, business conduct and commercial traps.
Additional evidence review
Source coverage and freshness
Status shows whether usable evidence was saved; finding shows what that evidence observed.
| Source | Result | Completion | Finding | Freshness |
|---|---|---|---|---|
| Antivirus | 19 of 92 engines flagged | Completed | Adverse | fresh · Jul 28, 2026 |
| Browser protection | No browser threat-list match | Completed | No adverse finding | Not available |
| Page content | Page fetched · HTTP 200 | Completed | No adverse finding | Not available |
| Visual evidence | No usable visual evidence was saved | Unavailable | No saved finding | Not available |
| Independent research | Independent research was not available for this report | Unavailable | No saved finding | Not available |
- Page content
- Result: Page fetched · HTTP 200
- Completed
- No adverse finding
- Visual evidence
- Result: No usable visual evidence was saved
- Unavailable
- No saved finding
- Independent research
- Result: Independent research was not available for this report
- Unavailable
- No saved finding
07 · Community
Community
08 · Safety FAQ
Safety FAQ
Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.
0 community contributions
Share what happened, what the site requested, and what others should watch for.
Community reviews never change the scanner verdict.