xaman[.]events
“Check your $XMN allocation | Xaman”
Evidence Summary
This domain is flagged as a high-risk generic phishing threat and is currently active as of the report date. The domain xaman.events was created on July 31, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Infrastructure analysis shows the domain resolves to IP address 104.21.58.247, which is associated with Cloudflare's hosting and CDN services, and its nameservers are ezra.ns.cloudflare.com and poppy.ns.cloudflare.com. The use of Cloudflare is common among both legitimate and malicious domains, so it does not by itself confirm or refute the threat classification.
Google Safe Browsing flags this domain for social engineering, which is a strong indicator that the site is designed to deceive visitors into taking unsafe actions, such as revealing credentials or downloading malicious content. The domain also appears on one security blocklist and is specifically blocked by PhishDestroy, a security vendor that tracks phishing infrastructure. VirusTotal scanned this domain with 91 vendors, and while zero vendors currently flag it, the absence of detections is not proof of safety, particularly when other independent sources have already identified malicious behavior.
The exact content of the website has not yet been analyzed, so no page title, brand, or specific scam category is available. The threat type is classified as generic phishing, meaning no particular brand or service has been identified as the impersonation target. This is a relatively new domain, created only days before the report date, which is consistent with the short-lived nature of many phishing operations that cycle through domains to evade takedowns.
Defenders should treat this domain as hostile. Access should be blocked at the network or DNS level, and users should be warned if they attempt to visit it. The domain should be monitored for changes in DNS records, IP resolution, or content, as these may indicate the operator shifting infrastructure.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
9 monitored external feeds No match
Stored outcome evidence
Outcome & takedown attribution
- Outcome
live_content- Availability
content_live- Cause
content_served- Confidence
- 90%
- First observation
- Latest observation
Evidence SHA-256 237a98c1647b
Detection timeline
-
First recorded
First stored value: Reachable
-
Availability
First stored value: Unknown
d66b618578bc -
Google Safe Browsing
0 → 1
-
Availability
Unknown → Live content
b3cf465fb40a -
Availability
Live content → Unknown
83374d9d652c -
Availability
Unknown → Live content
d01204eb7749 -
Availability
Live content → Unknown
7cebcfd4071c -
Availability
Unknown → Live content
cc693c9585fd -
Availability
Live content → Unknown
ca255b61650a -
Availability
Unknown → Live content
3bd6941f7f0f
Show all (4)
-
Availability
Live content → Unknown
d8f7d37d7f95 -
Availability
Unknown → Live content
92aa0e8b0a32 -
Availability
Live content → Unknown
afa49a2b04dd -
Availability
Unknown → Live content
237a98c1647b
Community reports
Reported by 0 community members, first seen Aug 5, 2026
- Unique reported URLs
- 2
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Lookalike domains
151 stored lookalike domains
Show all (88)
Showing 100 of 151
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive