rabby-web[.]app
“Rabby Wallet | Extension Download | Login”
证据摘要
This domain, rabby-web.app, presents a high-risk credential-theft phishing threat targeting users of the Rabby cryptocurrency wallet. The site mimics the official Rabby interface, presenting a page titled 'Rabby Wallet | Extension Download | Login' to deceive visitors into entering sensitive account credentials or downloading malicious browser extensions. Such activity typically aims to harvest login details, private keys, or seed phrases, enabling attackers to gain unauthorized access to victims' digital assets and wallets. The impersonation is designed to exploit trust in the Rabby brand, increasing the likelihood of successful compromise for users unfamiliar with official distribution channels. Analysis indicates that rabby-web.app was registered on April 14, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with suspicious domains. The domain resolves to the IP address 109.205.56.90 and is hosted on infrastructure utilizing Nginx. Detection metrics reveal significant concern among security vendors, with 21 out of 95 flagging the domain as malicious on VirusTotal. Additionally, the domain appears on four distinct security blocklists and has been assigned a trust score of 25/100 by Scamadviser and 0/100 by Gridinsoft, further corroborating its malicious nature. The combination of recent registration, low trust scores, and high detection rates underscores the domain's role in active phishing operations. Users who have visited rabby-web.app or interacted with its content should take immediate action to mitigate potential risks. First, cease all interaction with the domain and avoid entering any credentials or downloading files. If login details or private keys were submitted, revoke access to any associated wallets or accounts and transfer assets to a new, secure wallet. Monitor accounts for unauthorized transactions and enable multi-factor authentication where possible. Additionally, scan local devices for malware using updated security tools, as phishing sites may deploy malicious payloads. Report the domain to relevant security communities and wallet providers to assist in broader threat mitigation efforts.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
-
VirusTotal
12 → 21
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
技术
识别出 1 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of rabby-web.app · checked Jun 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控