The domain app.rabby-addon.com was registered on June 15, 2026 through Squarespace Domains II LLC and remains active as of the report date, July 31, 2026. DNS resolution points to the single IPv4 address 64.29.17.65, and the authoritative name servers are listed as nse1.squarespacedns.com, nse2.squarespacedns.com, nse3.squarespacedns.com, and nse4.squ. The hosting infrastructure is therefore provided by Squarespace’s DNS platform, a service commonly used for legitimate web content as well as for malicious actors seeking rapid deployment. The domain appears on one public security blocklist and has been specifically blocked by the PhishDestroy filtering service, indicating that at least one external sinkhole has identified it as a phishing vector. VirusTotal records show that the domain was scanned by 91 security vendors, none of which reported a detection at the time of analysis; this absence of detections does not constitute evidence of benign intent and should be interpreted as a lack of current signatures rather than proof of safety.
Available intelligence does not include a retrieved page title, SSL certificate details, HTTP response codes, or Safe Browsing/OTX alerts, leaving the surface‑web presentation of the site unverified. Consequently, the precise phishing campaign mechanics—such as the targeted brand, credential‑harvesting form, or malicious payload—remain unknown. The combination of a recently created domain, use of a reputable DNS provider, and inclusion on a dedicated anti‑phishing blocklist suggests a deliberate effort to exploit the credibility of the Squarespace ecosystem for fraudulent purposes.
Defenders should add app.rabby-addon.com to internal blocklists, monitor DNS queries for the associated IP address, and enforce outbound filtering that references the PhishDestroy blocklist. Network traffic to the domain should be logged and, where feasible, redirected to a sandbox environment for safe examination.