rabby[.]pw
“Rabby Wallet - Multi-Chain Digital Asset Manager”
Зведення доказів
The domain rabby.pw was registered on 27 November 2025 through NameCheap, Inc. and is hosted on Cloudflare infrastructure (AS13335) with the public address 188.114.96.3, a location attributed to the United States. DNS resolution points to the Cloudflare nameservers meg.ns.cloudflare.com and rene.ns.cloudflare.com. No TLS certificate is presented, indicating that the site either never served HTTPS or the certificate was removed before the current offline state. The page title returned from the last known HTTP response was "Rabby Wallet - Multi-Chain Digital Asset Manager," suggesting an attempt to impersonate a cryptocurrency wallet service. The intelligence categorises the activity as a wallet/seed phishing campaign targeting the brand "across," consistent with a brand‑impersonation motive.
VirusTotal analysis recorded 11 detections out of 93 scanning engines, confirming that multiple security vendors consider the domain malicious. It is listed on the PhishDestroy blocklist and appears on one additional security blocklist, reinforcing the assessment of malicious intent. The current operational status is offline, which limits further content inspection; however, the lack of an SSL certificate and the presence on phishing blocklists imply that the site was never intended to provide a trusted user experience.
Defenders should continue to block rabby.pw at perimeter controls, DNS filtering, and endpoint protection layers. Monitoring of the associated IP address 188.114.96.3 for any re‑use in future campaigns is advisable, given the Cloudflare hosting context. Because the domain is already flagged by multiple vendors, threat‑intel feeds should be updated to include rabby.pw as a confirmed wallet‑phishing indicator. Continuous re‑evaluation is recommended in case the domain becomes active again or the underlying infrastructure is repurposed for related attacks.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога