xamanwindowswallet.com
“Xaman Desktop - Secure XRP Wallet for Your Computer”
Evidence Summary
This domain is flagged as a high-risk crypto drainer targeting cryptocurrency users through a fraudulent XRP wallet interface. Analysis indicates the site impersonates legitimate desktop wallet software to trick victims into connecting their wallets, enabling unauthorized fund transfers to attacker-controlled addresses. The threat type is explicitly classified as a crypto drainer due to its focus on depleting digital asset holdings without user consent. Infrastructure analysis reveals the domain xamanwindowswallet.com resolves to IP address 91.92.241.250 and was registered through Squarespace Domains LLC on June 20, 2026. Security vendor detections on VirusTotal report 17/95 flags, with Google Safe Browsing specifically categorizing the domain under SOCIAL_ENGINEERING. The domain appears on one security blocklist and is currently blocked by InversionDNS. A Let's Encrypt SSL certificate provides HTTPS encryption, which may be used to lend false legitimacy to the phishing site. Mitigation against this crypto drainer threat requires immediate action from both end users and network administrators. Users should avoid interacting with the domain and revoke any wallet connections made to it. Wallet software should be verified through official distribution channels only, and browser-based security warnings must not be bypassed. Network-level protections should include DNS filtering to block resolution of the domain and its associated IP address. Cryptocurrency holders are advised to monitor their transaction histories for unauthorized activity and consider migrating funds to new wallet addresses if exposure is suspected.
Network Security Intelligence
Forensic History & Detection Timeline
-
Domain Status Transition Aug 6, 2026 · 00:00 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of xamanwindowswallet.com · checked Jul 2, 2026
Evidence & External Reports
PD-20260702-15002C Recipient: abuse@omegatech.sc Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive