rubic-exchange[.]co
“Rubic Exchange | Crypto Bridge”
Зведення доказів
This domain, rubic-exchange.co, operates as a fraudulent cryptocurrency bridge platform designed to harvest wallet credentials and private keys. Analysis indicates the site presents itself as a legitimate crypto exchange interface, tricking users into entering sensitive login details or connecting their digital wallets. The primary threat involves direct financial theft, as compromised credentials enable attackers to drain funds from victims' accounts without authorization. Infrastructure analysis reveals multiple technical indicators confirming malicious intent. The domain is flagged by 15 out of 95 security vendors on VirusTotal, with detections from specialized cryptocurrency security engines. It appears on three independent security blocklists and resolves to the IP address 130.12.180.128, which has been associated with previous phishing campaigns. The site uses a Let's Encrypt SSL certificate (serial number E7), a common tactic among phishing sites to appear legitimate while encrypting stolen data in transit. Domain registration details show it was created recently through a privacy-protected registrar, obscuring ownership while maintaining operational security. If you have visited rubic-exchange.co or entered any credentials on the site, immediate action is required. First, disconnect any wallets connected to the site and revoke all associated smart contract approvals using a blockchain explorer. Next, transfer all remaining funds to a new, secure wallet address that has never interacted with the phishing domain. Monitor all connected accounts for unauthorized transactions and enable additional security measures such as hardware-based authentication. Report the incident to your wallet provider and relevant blockchain security teams to help prevent further attacks. Users should also scan their devices for malware, as some phishing sites deploy additional payloads to maintain persistent access.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260609-9D3C5F- Заголовок збереженої сторінки
- Rubic Exchange | Crypto Bridge & DEX Aggregator
- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
Технології
Виявлено 2 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога