app[.]xrpl-split[.]xyz
“Cold Storage in Your Pocket | Xaman”
Evidence Summary
The domain app.xrpl-split.xyz is currently classified as an active generic phishing site with an elevated risk rating. Infrastructure analysis indicates that the domain has been intercepted by PhishDestroy, demonstrating that at least one dedicated anti‑phishing service has identified malicious activity associated with it. VirusTotal reports that 2 of 91 security vendors flagged the domain, providing independent corroboration of its malicious nature.
Additionally, the domain appears on a single security blocklist, further confirming its reputation as a threat vector. No public registrar information, IP address, hosting provider, or SSL certificate details are available in the supplied intelligence, and the page title or brand targeting has not been disclosed, limiting the depth of technical profiling. Given the limited but consistent evidence—multiple vendor detections, blocklist inclusion, and active blocking by PhishDestroy—defenders should treat the domain as hostile.
Recommended mitigations include adding app.xrpl-split.xyz to network and endpoint URL filtering policies, updating intrusion detection signatures to block outbound connections, and monitoring DNS query logs for any resolution attempts. Continuous re‑evaluation is advised, as additional indicators such as hosting infrastructure or content analysis may emerge, allowing for more precise attribution and response actions.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260804-30E1A4- PDF artifact
- PDF evidence
Full evidence text
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Stored outcome evidence
Outcome & takedown attribution
- Outcome
unknown- Availability
unreachable- Cause
origin_unreachable- Mechanism
http_5xx- Confidence
- 20%
- First observation
- Latest observation
Estimated unavailability
Time to unavailability: 0 hEvidence SHA-256 8324eee49b98
Detection timeline
-
First recorded
First stored value: Reachable
-
Availability
First stored value: DNS inactive
f93a11f87e4d -
Availability
DNS inactive → Unknown
9d08ed172a04 -
Domain status
Reachable → Unreachable
-
Availability
Unknown → DNS inactive
53d97bf626e0 -
Availability
DNS inactive → Held
ae5cfb2696f2 -
Availability
Held → DNS inactive
f52d526b76a1 -
Availability
DNS inactive → Unknown
a112b2bcdb35 -
Availability
Unknown → DNS inactive
6dfe9145995c -
Availability
DNS inactive → Unknown
a0d1a2ac90ab
Show all (2)
-
Availability
Unknown → DNS inactive
d0b7046e8c2f -
Availability
DNS inactive → Unknown
8324eee49b98
Community reports
Reported by 0 community members, first seen Aug 4, 2026
- Unique reported URLs
- 1
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Registration: xrpl-split.xyz
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain xrpl-split.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive