rabby-wallet[.]com
“404: NOT_FOUND”
Kanıt özeti
The domain rabby-wallet.com was registered through Tucows Domains Inc. on August 16, 2025 and is currently listed as offline. DNS resolution points to the Amazon‑owned address 64.29.17.1, which belongs to AS16509 (Amazon.com, Inc.) and is hosted in the United States. The authoritative name servers are 1-you.njalla.no, 2-can.njalla.in, and 3-get.njalla.fo, indicating the use of the Njalla privacy‑focused registrar service. The site presented an HTTP 404 response with the page title “404: NOT_FOUND”, and the TLS handshake was terminated by a Let’s Encrypt R12 certificate, confirming the presence of valid encryption but not necessarily legitimacy. Infrastructure analysis shows the site was built on Vercel and enforced HSTS, a combination frequently observed in legitimate web services but also leveraged by malicious actors to convey trust.
Threat intelligence flags the domain as a crypto‑related scam impersonating the Rabby brand. Four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—have each added the domain to their watchlists, and VirusTotal recorded 11 detections out of 95 scanned security vendors. No additional public Safe Browsing or OTX entries were observed in the available data set. The convergence of a recent registration, rapid inclusion on multiple blocklists, and a modest number of vendor detections suggests an active abuse campaign that was taken down shortly after deployment, as indicated by the current offline status.
Defenders should treat any traffic to rabby-wallet.com as malicious. Immediate actions include updating firewall and proxy deny lists to block the IP 64.29.17.1 and the domain name, incorporating the four named blocklists into automated URL filtering solutions, and monitoring for any newly registered domains that resolve to the same Njalla name servers or share the Vercel hosting fingerprint.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
7 izlenen harici kaynak Eşleşme yok
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Alan adı durumu
Erişilemiyor → Erişilebilir
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin