extension-rabby[.]com
“Rabby Wallet”
Analysis of extension-rabby.com indicates a brand impersonation phishing domain targeting Rabby, a cryptocurrency wallet service. The domain was registered on March 24, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, and is currently offline as of the report date. Infrastructure analysis reveals the domain resolved to IP address 188.114.97.3, hosted by Cloudflare, Inc. in Canada, with nameservers ruth.ns.cloudflare.com and tanner.ns.cloudflare.com. The site was served via Cloudflare with HTTP/3 support and utilized Plesk with PHP, as detected through technology fingerprinting. The SSL certificate was issued under the common name 'Plesk,' a pattern often observed in automated or low-effort phishing setups.
The page title 'Rabby Wallet' directly matches the brand targeted, confirming the intent to deceive users into believing the site is the legitimate Rabby service. Detection by security vendors is limited but notable: four of 95 security engines on VirusTotal flagged the domain as malicious. Additionally, the domain appears on two security blocklists, including PhishDestroy and ScamSniffer, which specialize in phishing and scam detection. Gridinsoft assigned a trust score of 0/100, reinforcing the assessment of elevated risk.
While the domain is currently offline, defenders should treat any future resolution or DNS changes with caution. The combination of brand-specific page title, low trust scores, and blocklist presence provides concrete evidence of malicious intent. Organizations should ensure endpoint protection and email filtering systems are updated to block this domain and any associated infrastructure. Further monitoring of the registrar and hosting provider may reveal related malicious domains using similar patterns.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260324-DE1D3F- Titel der erfassten Seite
- Rabby Wallet
- PDF-Artefakt
- PDF-Beweis
Vollständiger Beweistext
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Erkenntnisse zur Netzwerksicherheit Registrar context
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 Quellen · synchronisiert am 10.08.2026
Erkennungszeitleiste
-
Verfügbarkeit
stage4.timeline.first_value
f93a11f87e4d -
Verfügbarkeit
stage4.timeline.transition
104189c23da7 -
Verfügbarkeit
stage4.timeline.transition
dc98770e60c0 -
Verfügbarkeit
stage4.timeline.transition
67c20189038d -
Verfügbarkeit
stage4.timeline.transition
f52d526b76a1 -
Verfügbarkeit
stage4.timeline.transition
deb31d957d98 -
Verfügbarkeit
stage4.timeline.transition
37ac26f4e12e -
Verfügbarkeit
stage4.timeline.transition
42d4c8f8f33e -
Verfügbarkeit
stage4.timeline.transition
6dfe9145995c -
Verfügbarkeit
stage4.timeline.transition
f769565c344b
Alle anzeigen (6)
-
Verfügbarkeit
stage4.timeline.transition
641ed81dc4d5 -
Verfügbarkeit
stage4.timeline.transition
2d8934c8e2d2 -
Verfügbarkeit
stage4.timeline.transition
8b01057d79ef -
Verfügbarkeit
stage4.timeline.transition
e2cd440c89da -
Verfügbarkeit
stage4.timeline.transition
d0b7046e8c2f -
Verfügbarkeit
stage4.timeline.transition
2fa60f88cd5b
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensische Erkenntnisse
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of extension-rabby.com · checked Mar 24, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt