rabby[.]wallet-login[.]live
“Rabby Wallet | Extension Download | Login”
rabby.wallet-login.live — Контент недоступен (HTTP 502). Олицетворение бренда: Rabby; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 3/93 (ChainPatrol, Fortinet, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On 23 February 2026 the domain rabby.wallet-login.live was registered. The site was observed serving a page titled “Rabby Wallet | Extension Download | Login”, clearly targeting users of the Rabby cryptocurrency wallet extension. The page title and the brand target indicate a brand‑impersonation crypto scam aimed at harvesting credentials or installing malicious extensions. No TLS certificate was presented, meaning the site operated over plain HTTP, which further reduces user trust. Infrastructure analysis shows the domain resolves to IP address 188.114.96.3, an address owned by Cloudflare, Inc. (AS13335) and located in the United States. The hosting provider does not appear to be directly compromised, but the use of a reputable CDN suggests the operators sought anonymity and rapid content delivery.
Detection data from VirusTotal records three of ninety‑three antivirus engines flagging the domain as malicious, corroborating the suspicion of malicious intent. The domain is listed on three external blocklists and has been actively blocked by the phishing‑specific services PhishDestroy, MetaMask, and SEAL. These multiple independent detections increase confidence that the site is part of an organized impersonation campaign rather than a one‑off typo‑squatting test. The site’s current status is offline, indicating that the operators have either removed the content or are rotating infrastructure. Because the domain was active for only a few months, the full scope of the campaign—such as additional landing pages, associated command‑and‑control servers, or the malware payload delivered—remains unknown.
No evidence of additional infrastructure, such as secondary domains or email‑based phishing kits, has been disclosed. Defenders should add rabby.wallet-login.live to URL filtering and domain block lists across web gateways, DNS resolvers, and endpoint protection solutions. Monitoring for new domains that share the “wallet-login.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание