xamandesktop[.]io
“Xaman – The Best XRP Wallet for Security”
Résumé des preuves
Analysis as of July 24, 2026 indicates that xamandesktop.io was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is currently active. DNS resolution points to 216.150.1.1, an Amazon Web Services address (AS16509) located in the United States. The domain is served behind Cloudflare nameservers (jessica.ns.cloudflare.com, chuck.ns.cloudflare.com) and delivers HTTP 307 redirects, suggesting intentional traffic forwarding. The site presents a TLS certificate issued by Let’s Encrypt (R12) and advertises HSTS, yet the Gridinsoft trust score is 0/100, reflecting a lack of reputation.
Automated fingerprinting identified Vercel and LiveChat components, common to many legitimate web applications but also frequently abused in fraudulent deployments. The page title “Xaman – The Best XRP Wallet for Security” directly references the Xaman brand, confirming a brand‑impersonation motive aimed at cryptocurrency users. VirusTotal analysis shows that 3 of 93 security engines flag the domain, and it is listed on three external blocklists, including PhishDestroy, MetaMask, and SEAL, reinforcing its malicious classification as a crypto scam.
While the exact phishing mechanics have not been publicly disclosed, the convergence of brand‑targeted naming, low trust score, redirection behavior, and multiple vendor detections provides strong evidence of an active malicious infrastructure. Defenders should block the domain and its resolving IP at DNS and proxy layers, monitor outbound connections to the AWS address, enforce strict TLS validation, and update endpoint protection signatures to include the reported indicators. User awareness campaigns should emphasize that any unsolicited request promising Xaman wallet services, especially those directing to this domain, is likely fraudulent.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260204-85A251- Artefact PDF
- Preuve PDF
Texte intégral des preuves
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Historique des signalements 1
- Signalement 2 ⚠️ ESCALATION #2 (2746h active): Phishing - xamandesktop[.]io
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
VirusTotal
3 → 4
-
État du domaine
Accessible → Inaccessible
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of xamandesktop.io · checked Mar 6, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif