web-rabby-wallet-app[.]pages[.]dev
“Worker threw exception | web-rabby-wallet-app.pages.dev | Cloudflare”
Сводка доказательств
This domain, web-rabby-wallet-app.pages.dev, is an active phishing site impersonating Rabby, a cryptocurrency wallet service. Registered through Cloudflare, Inc. on August 23, 2025, the domain currently resolves to the IP address 188.114.97.3, associated with AS13335 (Cloudflare, Inc.) in the United States. The site is flagged on three security blocklists and has been identified as a crypto scam by multiple detection engines, including PhishDestroy, MetaMask, and SEAL. Gridinsoft assigns it a trust score of 0/100, further indicating malicious intent. Infrastructure analysis reveals the use of Cloudflare nameservers (dave.ns.cloudflare.com and summer.ns.cloudflare.com) and an SSL certificate issued by Cloudflare TLS Issuing ECC CA 3. The domain employs HTTP/3 and HSTS, which are common among legitimate services but are also leveraged here to lend an appearance of authenticity. The HTTP status code 500, accompanied by the page title 'Worker threw exception,' suggests either a misconfiguration or an intentional error state, potentially to obscure the site's true functionality from automated analysis. While the domain is detected by one of 93 security vendors on VirusTotal, the limited detection count does not diminish the confirmed malicious classification. The site's registration details, combined with its presence on multiple blocklists and its impersonation of a cryptocurrency wallet, align with known tactics for crypto-related phishing campaigns. Defenders should treat this domain as high-risk and prioritize blocking it at the network and endpoint levels. Further investigation into associated infrastructure, such as linked IP addresses or domains, is recommended to identify related threats. The domain remains active as of July 12, 2026, and no evidence suggests it has been taken down.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание