web-rabby[.]org
Análisis de phishing y seguridad de web-rabby.org
“Rabby Wallet: Secure Crypto Management Made Simple”
web-rabby.org — Contenido no disponible (HTTP 502). Suplantación de marca: Across; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 14/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 92/100. Registrador: Web Commerce Communica….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain web-rabby.org indicates that it was actively used for a crypto‑related brand‑impersonation campaign targeting users of the Rabby wallet. The site was registered on 21 February 2026 through Web Commerce Communications Limited dba WebNic.cc and uses the authoritative name servers ns100.webnic.cc and ns101.webnic.cc. DNS resolution points to the IPv4 address 87.120.126.210, which is announced by AS215730 (H2NEXUS LTD) and geolocated to Germany. The site presented the page title “Rabby Wallet: Secure Crypto Management Made Simple”, matching the advertised service and confirming the intent to masquerade as the legitimate Rabby wallet offering.
The domain has been flagged by multiple detection sources: PhishDestroy lists it as blocked, it appears on one public security blocklist, and AlienVault OTX includes it in a single threat‑intel pulse. VirusTotal scans show that 14 of 93 security engines flagged the domain as malicious, reinforcing the suspicion of malicious activity. The SSL certificate is identified as “R11”, indicating that HTTPS was provisioned, likely to increase credibility. As of the report date (23 July 2026) the site is offline, but the infrastructure remains observable.
Uncertainty remains regarding the exact phishing kit or the extent of victim data exfiltration, as no page content or traffic logs have been released. Defenders should continue to block the domain and its hosting IP at perimeter and endpoint layers, add the associated IP range to reputation feeds, and monitor for any resurgence of the domain or similar registrants using the same registrar or name‑server pair. Incident response teams should also file indicators of compromise with local CERTs to aid in broader attribution efforts. Ongoing intelligence collection should focus on correlating future sightings of the AS215730 block, as well as tracking any new OTX pulses that reference the same brand impersonation pattern.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.