derivetivaex[.]cc
“Uniswap”
Zusammenfassung der Beweislage
Analysis of the domain derivetivaex.cc indicates it was actively used in a crypto scam impersonating Ethereum and presenting a page titled 'Uniswap'. The domain was registered on October 13, 2025, through Gname.com Pte. Ltd. and resolved to the IP address 172.67.205.104, which is part of Cloudflare's infrastructure (AS13335) located in the US. The SSL certificate was issued by WE1, a low-assurance provider commonly associated with ephemeral phishing sites. At the time of reporting, the domain has been taken offline, though its infrastructure remains documented in threat intelligence sources.
Defensive checks reveal elevated risk: Gridinsoft assigned a trust score of 0/100, and the domain appears in three AlienVault OTX threat intelligence pulses, confirming its classification as malicious. Fourteen of 93 security vendors on VirusTotal flagged the domain, reinforcing its fraudulent nature. It was also blocked by PhishDestroy and listed on one additional security blocklist. The use of Cloudflare hosting is consistent with threat actors leveraging content delivery networks to obscure origin servers and evade takedowns.
While the exact content of the site remains unanalyzed, the available metadata—including the 'Uniswap' page title and explicit targeting of Ethereum—strongly suggests a cryptocurrency drainer or wallet-credential harvesting scheme. Defenders should treat any prior resolution of this domain as a high-confidence indicator of compromise. Network security teams are advised to block the domain and its associated IP at perimeter controls, and to review logs for connections to 172.67.205.104 during the period it was active. Given the domain's offline status, further forensic analysis may be limited, but its registration and hosting patterns align with known crypto-phishing infrastructure.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Forensische Erkenntnisse
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt