rabby[.]pw
“Rabby Wallet - Multi-Chain Digital Asset Manager”
rabby.pw — Conteúdo indisponível (HTTP 502). Representação da marca: Across; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 11/93 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, G-Data); PhishDestroy score 83/100. Registrador: NameCheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain rabby.pw was registered on 27 November 2025 through NameCheap, Inc. and is hosted on Cloudflare infrastructure (AS13335) with the public address 188.114.96.3, a location attributed to the United States. DNS resolution points to the Cloudflare nameservers meg.ns.cloudflare.com and rene.ns.cloudflare.com. No TLS certificate is presented, indicating that the site either never served HTTPS or the certificate was removed before the current offline state. The page title returned from the last known HTTP response was "Rabby Wallet - Multi-Chain Digital Asset Manager," suggesting an attempt to impersonate a cryptocurrency wallet service. The intelligence categorises the activity as a wallet/seed phishing campaign targeting the brand "across," consistent with a brand‑impersonation motive.
VirusTotal analysis recorded 11 detections out of 93 scanning engines, confirming that multiple security vendors consider the domain malicious. It is listed on the PhishDestroy blocklist and appears on one additional security blocklist, reinforcing the assessment of malicious intent. The current operational status is offline, which limits further content inspection; however, the lack of an SSL certificate and the presence on phishing blocklists imply that the site was never intended to provide a trusted user experience.
Defenders should continue to block rabby.pw at perimeter controls, DNS filtering, and endpoint protection layers. Monitoring of the associated IP address 188.114.96.3 for any re‑use in future campaigns is advisable, given the Cloudflare hosting context. Because the domain is already flagged by multiple vendors, threat‑intel feeds should be updated to include rabby.pw as a confirmed wallet‑phishing indicator. Continuous re‑evaluation is recommended in case the domain becomes active again or the underlying infrastructure is repurposed for related attacks.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo