eomf[.]deribitltd[.]cc
“Deribit”
Resumo das evidências
This domain, eomf.deribitltd.cc, is a confirmed brand impersonation phishing site targeting the cryptocurrency exchange brand Deribit, as indicated by the page title 'Deribit' and the scam classification in threat intelligence sources. Registered on December 10, 2025, through Gname.com Pte. Ltd., the domain resolved to IP 188.239.22.205, hosted on AS136907 (HUAWEI CLOUDS) in Singapore. Nameservers a4.share-dns.com and b4.share-dns.net were in use, a configuration often observed in low-reputation or bulletproof hosting environments. Analysis reveals the domain was flagged by 14 of 93 security vendors on VirusTotal, while Google Safe Browsing classified it as social engineering.
The domain appears on at least one security blocklist and was assigned a trust score of 0/100 by Gridinsoft. No SSL certificate was detected, increasing the likelihood of interception or user distrust. The domain was blocked by PhishDestroy and is currently offline as of the report date, though historical resolution and detection data remain relevant for retrospective threat hunting. Defenders should treat this domain as high-risk for Deribit brand impersonation, particularly in cryptocurrency-related phishing campaigns.
The infrastructure—hosting provider, nameservers, and lack of encryption—aligns with patterns used in credential harvesting or fraudulent transaction schemes. Network defenders are advised to block the domain, IP, and associated nameservers at perimeter controls. Security teams should review logs for connections to 188.239.22.205 or DNS queries for eomf.deribitltd.cc, particularly from endpoints involved in cryptocurrency transactions or financial operations. No further page content analysis is available; additional context may emerge from endpoint or proxy logs.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
VirusTotal
8 → 14
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo