mail[.]rabbywebextensions[.]io
“Rabby Wallet”
ملخص الأدلة
The domain mail.rabbywebextensions.io was registered on March 13, 2026 through Sav.com, LLC and is presently taken offline. Infrastructure analysis shows the domain resolves to IP address 163.61.188.5, which is announced by AS153568 NEW DHAKA HARDWARE and geolocated to the United States. DNS resolution is handled by four lytehosting.com nameservers (dns1‑dns4.lytehosting.com). The site served a TLS certificate issued by Let’s Encrypt under the R12 profile, confirming the use of a publicly trusted certificate.
Web‑server technology identified includes LiteSpeed with Cloudflare front‑end services, while the front‑end code base incorporates Bootstrap, jQuery, jsDelivr, cdnjs, Google Analytics, and EmailJS. The page title returned by the server was "Rabby Wallet," directly indicating an attempt to impersonate the Rabby brand. VirusTotal scans recorded two positive detections out of 94 security vendors, and the domain appears on three public blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple anti‑phishing services have flagged the site.
Reputation services assign a Gridinsoft trust score of 0 / 100, underscoring a lack of legitimacy. The threat is classified as a crypto‑related scam employing brand impersonation. While the offline status prevents real‑time interaction, defenders should continue to monitor the associated IP address and ASN for any reactivation, enforce blocking of the domain at network perimeter and DNS layers, and update phishing‑detection signatures to include the observed page title and certificate details. Additional investigation is required to determine whether any credential‑harvesting endpoints were ever active before takedown, but the available evidence already supports high‑confidence mitigation actions.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
0 ← 1
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of mail.rabbywebextensions.io · checked Mar 16, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب