web-rabbyio[.]wstd[.]io
“Rabby Wallet (Official) | Getting Started with Rabby”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain, web-rabbyio.wstd.io, is identified as a high-risk brand impersonation threat targeting Rabby, a cryptocurrency wallet service. Analysis indicates the site presented itself as an official Rabby Wallet portal, using the page title 'Rabby Wallet (Official) | Getting Started with Rabby' to deceive users into interacting with fraudulent content. No direct evidence of a crypto drainer kit was observed, but the domain’s structure and branding align with tactics commonly used to harvest credentials or distribute malicious payloads under the guise of legitimate services.
Technical indicators confirm the domain’s malicious nature. It was registered on February 21, 2026, through NameCheap, Inc., and resolved to the IP address 104.19.163.34, hosted on Cloudflare’s infrastructure (AS13335). VirusTotal detections show 10 out of 95 security vendors flagging the domain as malicious, while Google Safe Browsing explicitly labels it as phishing. The domain appears on one security blocklist, and its SSL certificate, issued by Let’s Encrypt (serial number E8), does not mitigate its fraudulent intent. The use of Cloudflare’s services further complicates attribution and takedown efforts due to the provider’s widespread legitimate use.
As of the latest assessment, web-rabbyio.wstd.io has been taken offline, likely due to enforcement actions by security providers or hosting interventions. However, the risk of re-emergence persists, as threat actors frequently re-register similar domains or migrate infrastructure. Users and organizations are advised to monitor for lookalike domains, particularly those combining 'rabby' with obfuscated TLDs or subdomains. Network-level blocking of the resolved IP (104.19.163.34) and implementation of strict SSL certificate validation policies can mitigate residual exposure. Security teams should prioritize awareness training to educate users on identifying brand impersonation tactics, such as scrutinizing domain names for subtle misspellings or unusual top-level domains.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание