xmrwaallet[.]com
“Best Monero Wallet (XMR) - Send & Receive Monero Securely”
Resumen de las pruebas
Analysis of the domain xmrwaallet.com indicates it was deployed as a crypto‑focused phishing operation targeting Monero users. The site was registered on 21 February 2026 through MAT BAO CORPORATION and resolved to the IP address 85.192.48.109, which is assigned to H2NEXUS LTD in Finland (AS215730). Nameservers ns1.guatda.com and ns2.guatda.com were configured for the domain. No TLS certificate was observed, meaning the site operated without encryption.
The page title returned by the server, "Best Monero Wallet (XMR) - Send & Receive Monero Securely," aligns with the reported use of a Seed Phrase Phishing kit, a known method for exfiltrating cryptocurrency recovery phrases. VirusTotal scans recorded 2 detections out of 95 security vendors, confirming that at least a subset of scanners flagged the domain as malicious. The domain appears on a single security blocklist and was actively taken down by the PhishDestroy mitigation service, with its current status marked as offline. While the available data confirms the presence of a crypto‑scam infrastructure, details such as the exact payload, the phishing page layout, or additional command‑and‑control hosts remain undisclosed.
Defenders should continue to block the IP 85.192.48.109 and the domain xmrwaallet.com at network perimeters, update URL filtering lists, and monitor for any re‑registration attempts. Observers should also watch for other domains using the same registrar, nameservers, or hosting provider, as they may indicate a broader campaign. Given the elevated risk rating, threat‑intel sharing with downstream security partners is recommended to accelerate detection and response.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260217-AC1D8E- Título de la página capturada
- Best Monero Wallet (XMR) - Send & Receive Monero Securely
Fundamento jurídico
Texto completo de la evidencia
Acceptable Use Policy (AUP): The domain xmrwaallet.com is actively engaged in phishing activities, which constitutes a direct violation of the AUP prohibiting illegal activities and fraud.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations. The ongoing phishing operations associated with this domain warrant immediate action under this provision.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and networks, which is applicable to phishing schemes that deceive users into providing sensitive information.
Wire Fraud Statute (18 U.S.C. § 1343): This statute criminalizes schemes to defraud individuals via electronic communications, including phishing attacks.
CAN-SPAM Act (15 U.S.C. § 7701): This law regulates commercial email and prohibits deceptive practices, including misleading subject lines and sender information, which are often employed in phishing attempts.
Regulatory Note: Failure to take appropriate action against xmrwaallet.com may expose your organization to legal liability and regulatory scrutiny. Immediate compliance with your AUP and TOS is essential to mitigate potential risks.
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www.xmrwalllet.com |
malicious | Sinkholed |
| Hagezi Threat Feed | xmrwaallet.com |
malicious | Sinkholed |
| Hagezi Threat Feed | xmrwalllet.com |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.