rabby-vallet[.]vercel[.]app
“Rabby Wallet™ | Home Official Site”
rabby-vallet.vercel.app — Encoberto · alcançável. Representação da marca: Rabby; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 10/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 100/100. Registrador: Tucows.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates this infrastructure is HIGH risk due to active brand impersonation of Rabby combined with a fake login and crypto drainer delivery pattern. The page is explicitly crafted to resemble an official wallet entry point, with the title "Rabby Wallet™ | Home Official Site" used to increase trust and induce credential or asset exposure.
Threat intelligence shows multiple corroborating indicators of malicious activity. VirusTotal reports 12/95 security vendors flagging the domain. The domain is registered through Tucows Domains Inc. It resolves to IP 216.198.79.195 and is hosted within AS16509 Amazon.com, Inc. Infrastructure metadata shows a creation date of February 21, 2026, and the domain remains active at time of analysis. It appears on 3 security blocklists and is additionally blocked by PhishDestroy, MetaMask, and SEAL. SSL issuance is attributed to Google Trust Services / WR1. Google Safe Browsing also flags the domain as phishing. Collectively, these signals indicate sustained malicious hosting and active detection across multiple independent security systems.
Mitigation should prioritize immediate blocking of the domain at DNS, proxy, and endpoint layers due to confirmed phishing and crypto drainer behavior. Users should be warned not to enter seed phrases, private keys, or authentication credentials on any page referencing this domain or similar lookalike infrastructure. Security teams should deploy IOC-based detection using the domain, resolved IP 216.198.79.195, and associated hosting ASN AS16509 to identify related deployments. Additional monitoring should focus on newly registered domains impersonating wallet services, especially those leveraging trusted SSL certificates such as Google Trust Services / WR1 to appear legitimate. Incident response workflows should treat any interaction with this domain as potential credential compromise and enforce immediate wallet migration and key rotation procedures where exposure is suspected.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
Popular CSS framework for responsive, mobile-first web development.
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of rabby-vallet.vercel.app · checked Mar 2, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo