rabby-wallet[.]com
“404: NOT_FOUND”
Зведення доказів
The domain rabby-wallet.com was registered through Tucows Domains Inc. on August 16, 2025 and is currently listed as offline. DNS resolution points to the Amazon‑owned address 64.29.17.1, which belongs to AS16509 (Amazon.com, Inc.) and is hosted in the United States. The authoritative name servers are 1-you.njalla.no, 2-can.njalla.in, and 3-get.njalla.fo, indicating the use of the Njalla privacy‑focused registrar service. The site presented an HTTP 404 response with the page title “404: NOT_FOUND”, and the TLS handshake was terminated by a Let’s Encrypt R12 certificate, confirming the presence of valid encryption but not necessarily legitimacy. Infrastructure analysis shows the site was built on Vercel and enforced HSTS, a combination frequently observed in legitimate web services but also leveraged by malicious actors to convey trust.
Threat intelligence flags the domain as a crypto‑related scam impersonating the Rabby brand. Four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—have each added the domain to their watchlists, and VirusTotal recorded 11 detections out of 95 scanned security vendors. No additional public Safe Browsing or OTX entries were observed in the available data set. The convergence of a recent registration, rapid inclusion on multiple blocklists, and a modest number of vendor detections suggests an active abuse campaign that was taken down shortly after deployment, as indicated by the current offline status.
Defenders should treat any traffic to rabby-wallet.com as malicious. Immediate actions include updating firewall and proxy deny lists to block the IP 64.29.17.1 and the domain name, incorporating the four named blocklists into automated URL filtering solutions, and monitoring for any newly registered domains that resolve to the same Njalla name servers or share the Vercel hosting fingerprint.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
7 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Недоступний → Доступний
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога