rabby-vallet[.]vercel[.]app
“Rabby Wallet™ | Home Official Site”
Gespeicherte Erkennung
Cloaking-Warnung
- Cloaking-Typ
content_split- Cloaking-Wert
- 1/6
Zusammenfassung der Beweislage
Analysis indicates this infrastructure is HIGH risk due to active brand impersonation of Rabby combined with a fake login and crypto drainer delivery pattern. The page is explicitly crafted to resemble an official wallet entry point, with the title "Rabby Wallet™ | Home Official Site" used to increase trust and induce credential or asset exposure.
Threat intelligence shows multiple corroborating indicators of malicious activity. VirusTotal reports 12/95 security vendors flagging the domain. The domain is registered through Tucows Domains Inc. It resolves to IP 216.198.79.195 and is hosted within AS16509 Amazon.com, Inc. Infrastructure metadata shows a creation date of February 21, 2026, and the domain remains active at time of analysis. It appears on 3 security blocklists and is additionally blocked by PhishDestroy, MetaMask, and SEAL. SSL issuance is attributed to Google Trust Services / WR1. Google Safe Browsing also flags the domain as phishing. Collectively, these signals indicate sustained malicious hosting and active detection across multiple independent security systems.
Mitigation should prioritize immediate blocking of the domain at DNS, proxy, and endpoint layers due to confirmed phishing and crypto drainer behavior. Users should be warned not to enter seed phrases, private keys, or authentication credentials on any page referencing this domain or similar lookalike infrastructure. Security teams should deploy IOC-based detection using the domain, resolved IP 216.198.79.195, and associated hosting ASN AS16509 to identify related deployments. Additional monitoring should focus on newly registered domains impersonating wallet services, especially those leveraging trusted SSL certificates such as Google Trust Services / WR1 to appear legitimate. Incident response workflows should treat any interaction with this domain as potential credential compromise and enforce immediate wallet migration and key rotation procedures where exposure is suspected.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of rabby-vallet.vercel.app · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt