rabby-wallet[.]com
“404: NOT_FOUND”
Résumé des preuves
The domain rabby-wallet.com was registered through Tucows Domains Inc. on August 16, 2025 and is currently listed as offline. DNS resolution points to the Amazon‑owned address 64.29.17.1, which belongs to AS16509 (Amazon.com, Inc.) and is hosted in the United States. The authoritative name servers are 1-you.njalla.no, 2-can.njalla.in, and 3-get.njalla.fo, indicating the use of the Njalla privacy‑focused registrar service. The site presented an HTTP 404 response with the page title “404: NOT_FOUND”, and the TLS handshake was terminated by a Let’s Encrypt R12 certificate, confirming the presence of valid encryption but not necessarily legitimacy. Infrastructure analysis shows the site was built on Vercel and enforced HSTS, a combination frequently observed in legitimate web services but also leveraged by malicious actors to convey trust.
Threat intelligence flags the domain as a crypto‑related scam impersonating the Rabby brand. Four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—have each added the domain to their watchlists, and VirusTotal recorded 11 detections out of 95 scanned security vendors. No additional public Safe Browsing or OTX entries were observed in the available data set. The convergence of a recent registration, rapid inclusion on multiple blocklists, and a modest number of vendor detections suggests an active abuse campaign that was taken down shortly after deployment, as indicated by the current offline status.
Defenders should treat any traffic to rabby-wallet.com as malicious. Immediate actions include updating firewall and proxy deny lists to block the IP 64.29.17.1 and the domain name, incorporating the four named blocklists into automated URL filtering solutions, and monitoring for any newly registered domains that resolve to the same Njalla name servers or share the Vercel hosting fingerprint.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
7 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Inaccessible → Accessible
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif