rappidbsr.com — Generic Phishing Infrastructure Report
Security analysis of rappidbsr.com covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
Analysis of rappidbsr.com shows a newly registered domain (creation date July 28, 2026) hosted on IP 75.2.60.5 and using GoDaddy.com, LLC as registrar with default domaincontrol.com nameservers. The domain appears on a single security blocklist and is actively blocked by PhishDestroy, indicating that threat‑intelligence feeds have flagged it as malicious. VirusTotal records demonstrate that the domain was submitted to 91 scanning engines, none of which raised a detection at the time of the query. While the absence of detections does not constitute a safety guarantee, the combination of blocklist inclusion and active blocking suggests a high likelihood of phishing use.
The infrastructure is typical of fast‑flux or low‑cost phishing campaigns that rely on recent registrations and reputable registrars to evade early scrutiny. No public SSL certificate details, HTTP response codes, or page‑title information are currently available, limiting the ability to confirm the exact content served. Likewise, Safe Browsing, OTX, and other reputation services have not published additional signals for this host.
Consequently, the primary uncertainties revolve around the specific payload or credential‑harvesting page hosted at the domain and whether the IP address is shared with other malicious actors. Defenders should add rappidbsr.com to internal blocklists, monitor outbound connections to 75.2.60.5, and enforce URL filtering that blocks the domain across web gateways. Continued observation of VirusTotal submissions, any emerging threat‑intel feeds, and DNS queries for the domain is recommended to detect potential escalation or reuse in broader campaigns.