rabbyy[.]myftp[.]org
“Rabby Wallet | Your Go-to Wallet for Ethereum and EVM”
rabbyy.myftp.org — Non vérifié. Usurpation de l'identité de la marque : Across; Type d'arnaque : Fake Airdrop. Résumé des preuves: VirusTotal 0/91; URLQuery 1 alert; PhishDestroy score 57/100. Bureau d’enregistrement: "Vitalwerks Internet S….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain www.rabbyy.myftp.org is a phishing site engaged in brand impersonation, specifically targeting users of the 'across' platform. It presents itself as a legitimate Rabby Wallet service for Ethereum and EVM chains but operates as an airdrop scam and wallet-connect phishing scheme. No crypto drainer kit was identified. The site is currently taken offline, but its prior activity posed an elevated risk to victims who may have connected wallets or shared credentials.
Technical indicators confirm the malicious nature of www.rabbyy.myftp.org. The domain was flagged by 1 of 95 VirusTotal security vendors, including Ermes, and appears on 1 security blocklist (PhishDestroy). It was registered through Vitalwerks Internet Solutions, LLC DBA No-IP on February 21, 2026, and resolves to the IP address 216.198.79.1, hosted in the US under AS16509 (Amazon.com, Inc.). No SSL certificate was issued, and the observed page title was 'Rabby Wallet | Your Go-to Wallet for Ethereum and EVM'. Nameservers include nf1.no-ip.com, nf2.no-ip.com, nf3.no-ip.com, and nf4.no-ip.com. Gridinsoft assigned a trust score of 0/100 to the domain.
Victims of www.rabbyy.myftp.org should immediately revoke any token approvals granted to the site and transfer funds to a new wallet to prevent unauthorized access. If credentials were entered, change passwords for all associated accounts and enable two-factor authentication (2FA). Monitor accounts for suspicious activity and report the phishing domain to platforms like Google Safe Browsing, PhishTank, or the impersonated brand's security team for further action.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | www.rabbyy.myftp.org/assets/index-ourwc5_u.js |
malware | Detects file containing Telegram Bot API |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif