derivetivaex[.]cc
“Uniswap”
Сводка доказательств
Analysis of the domain derivetivaex.cc indicates it was actively used in a crypto scam impersonating Ethereum and presenting a page titled 'Uniswap'. The domain was registered on October 13, 2025, through Gname.com Pte. Ltd. and resolved to the IP address 172.67.205.104, which is part of Cloudflare's infrastructure (AS13335) located in the US. The SSL certificate was issued by WE1, a low-assurance provider commonly associated with ephemeral phishing sites. At the time of reporting, the domain has been taken offline, though its infrastructure remains documented in threat intelligence sources.
Defensive checks reveal elevated risk: Gridinsoft assigned a trust score of 0/100, and the domain appears in three AlienVault OTX threat intelligence pulses, confirming its classification as malicious. Fourteen of 93 security vendors on VirusTotal flagged the domain, reinforcing its fraudulent nature. It was also blocked by PhishDestroy and listed on one additional security blocklist. The use of Cloudflare hosting is consistent with threat actors leveraging content delivery networks to obscure origin servers and evade takedowns.
While the exact content of the site remains unanalyzed, the available metadata—including the 'Uniswap' page title and explicit targeting of Ethereum—strongly suggests a cryptocurrency drainer or wallet-credential harvesting scheme. Defenders should treat any prior resolution of this domain as a high-confidence indicator of compromise. Network security teams are advised to block the domain and its associated IP at perimeter controls, and to review logs for connections to 172.67.205.104 during the period it was active. Given the domain's offline status, further forensic analysis may be limited, but its registration and hosting patterns align with known crypto-phishing infrastructure.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание