rubic-exchange[.]co
“Rubic Exchange | Crypto Bridge”
Kanıt özeti
This domain, rubic-exchange.co, operates as a fraudulent cryptocurrency bridge platform designed to harvest wallet credentials and private keys. Analysis indicates the site presents itself as a legitimate crypto exchange interface, tricking users into entering sensitive login details or connecting their digital wallets. The primary threat involves direct financial theft, as compromised credentials enable attackers to drain funds from victims' accounts without authorization. Infrastructure analysis reveals multiple technical indicators confirming malicious intent. The domain is flagged by 15 out of 95 security vendors on VirusTotal, with detections from specialized cryptocurrency security engines. It appears on three independent security blocklists and resolves to the IP address 130.12.180.128, which has been associated with previous phishing campaigns. The site uses a Let's Encrypt SSL certificate (serial number E7), a common tactic among phishing sites to appear legitimate while encrypting stolen data in transit. Domain registration details show it was created recently through a privacy-protected registrar, obscuring ownership while maintaining operational security. If you have visited rubic-exchange.co or entered any credentials on the site, immediate action is required. First, disconnect any wallets connected to the site and revoke all associated smart contract approvals using a blockchain explorer. Next, transfer all remaining funds to a new, secure wallet address that has never interacted with the phishing domain. Monitor all connected accounts for unauthorized transactions and enable additional security measures such as hardware-based authentication. Report the incident to your wallet provider and relevant blockchain security teams to help prevent further attacks. Users should also scan their devices for malware, as some phishing sites deploy additional payloads to maintain persistent access.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260609-9D3C5F- Yakalanan sayfa başlığı
- Rubic Exchange | Crypto Bridge & DEX Aggregator
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
Teknolojiler
2 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin