MALICIOUS — HIGH
1xv[.]pages[.]dev
This domain, 1xv.pages.dev, poses as the legitimate Rabby Wallet interface to deceive users into entering sensitive credentials or wallet recovery phrases.
- VirusTotal
- 0/91
- Blocklists
- 2 · MetaMask, SEAL
- उपलब्धता
- पहुंच योग्य · पहुंच प्रतिबंधित · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
1xv.pages.dev — पहुंच योग्य · पहुंच प्रतिबंधित (HTTP 403). ब्रांड प्रतिरूपण: Rabby; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 0/91; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. रजिस्ट्रार: Cloudflare.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
This domain, 1xv.pages.dev, poses as the legitimate Rabby Wallet interface to deceive users into entering sensitive credentials or wallet recovery phrases. Analysis indicates the site is designed to harvest login details, enabling unauthorized access to cryptocurrency wallets and potential asset theft. The page title explicitly mimics the official Rabby Wallet, increasing the likelihood of successful deception among users familiar with the brand. Infrastructure analysis reveals the domain was registered on August 09, 2025, through Cloudflare, Inc., and resolves to the IP address 172.66.47.101. It is flagged by 1 out of 95 security vendors on VirusTotal, with detections from MetaMask, PhishDestroy, and SEAL blocklists. The domain appears on three security blocklists, and its SSL certificate is issued by Google Trust Services. Technologies detected include HSTS and HTTP/3, suggesting an attempt to appear legitimate while obfuscating malicious intent. Users who visited 1xv.pages.dev should immediately revoke any permissions granted to the site in their wallet applications. Reset passwords and recovery phrases for any accounts or wallets accessed during the visit. Monitor connected wallets for unauthorized transactions and enable multi-factor authentication where available. If credentials were entered, assume compromise and transfer assets to a new, secure wallet. Report the incident to relevant security teams or platforms to aid in broader mitigation efforts.
डेटा कवरेज12 recorded checks
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of 1xv.pages.dev · checked Jun 26, 2026
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।