rabbitswap[.]io
rabbitswap.io — पहुंच योग्य · पहुंच प्रतिबंधित (HTTP 403). ब्रांड प्रतिरूपण: Rabby; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 3/91 (alphaMountain.ai, Fortinet, Gridinsoft); 4 external blocklist matches; PhishDestroy score 82/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain rabbitswap.io was registered through NiceNIC International Group Co., Limited on February 21 2026. It resolves to the Cloudflare IP address 188.114.96.3 (AS13335, United States) and uses Cloudflare’s DNS (jack.ns.cloudflare.com, meera.ns.cloudflare.com). The site presents a TLS certificate from Let’s Encrypt (E8) and returns HTTP 403 with the page title “Just a moment…”, which is typical of a Cloudflare challenge page. Infrastructure analysis shows a Node.js stack with Express, HSTS enabled, Cloudflare Browser Insights and HTTP/3 support, indicating a modern web server behind Cloudflare’s reverse‑proxy.
The domain is listed on seven security blocklists and is actively blocked by PhishDestroy, MetaMask, ScamSniffer, Polkadot, and SEAL. VirusTotal reports six detections out of ninety‑three scanned engines, and Gridinsoft assigns a trust score of 0 / 100, confirming a very low reputation. Intelligence tags the site as an “Airdrop Scam” and classifies the activity as a crypto‑scam that impersonates the Rabby brand. These indicators collectively place the domain in the high‑risk category for brand impersonation.
What remains uncertain is the exact content served after the Cloudflare challenge; the 403 response may be a protective block rather than the final malicious payload. Defenders should therefore block any network traffic to rabbitswap.io, add the domain to URL filtering and email security policies, and monitor DNS queries for the associated IP address. Users of the Rabby wallet should be warned not to visit the site or provide credentials. Ongoing re‑assessment with VirusTotal and other AV vendors is recommended to track changes in detection status.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
Latest Classified Outcome 2026-08-14 02:46:31 UTC
तकनीकें · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।