eomf[.]deribitltd[.]cc
“Deribit”
Сводка доказательств
This domain, eomf.deribitltd.cc, is a confirmed brand impersonation phishing site targeting the cryptocurrency exchange brand Deribit, as indicated by the page title 'Deribit' and the scam classification in threat intelligence sources. Registered on December 10, 2025, through Gname.com Pte. Ltd., the domain resolved to IP 188.239.22.205, hosted on AS136907 (HUAWEI CLOUDS) in Singapore. Nameservers a4.share-dns.com and b4.share-dns.net were in use, a configuration often observed in low-reputation or bulletproof hosting environments. Analysis reveals the domain was flagged by 14 of 93 security vendors on VirusTotal, while Google Safe Browsing classified it as social engineering.
The domain appears on at least one security blocklist and was assigned a trust score of 0/100 by Gridinsoft. No SSL certificate was detected, increasing the likelihood of interception or user distrust. The domain was blocked by PhishDestroy and is currently offline as of the report date, though historical resolution and detection data remain relevant for retrospective threat hunting. Defenders should treat this domain as high-risk for Deribit brand impersonation, particularly in cryptocurrency-related phishing campaigns.
The infrastructure—hosting provider, nameservers, and lack of encryption—aligns with patterns used in credential harvesting or fraudulent transaction schemes. Network defenders are advised to block the domain, IP, and associated nameservers at perimeter controls. Security teams should review logs for connections to 188.239.22.205 or DNS queries for eomf.deribitltd.cc, particularly from endpoints involved in cryptocurrency transactions or financial operations. No further page content analysis is available; additional context may emerge from endpoint or proxy logs.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
VirusTotal
8 → 14
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание