xamandesktopwallet[.]app
“Xaman Wallet Desktop - The Leading Self-Custody Wallet To Claim Glacier Drop For XRPL”
Résumé des preuves
Analysis of xamandesktopwallet.app as of 23 July 2026 shows a brand‑impersonation infrastructure targeting the Xaman cryptocurrency wallet brand. The domain was hosted on Amazon AWS under ASN 16509 and resolved to 64.29.17.1, a US‑based address. DNS resolution used Vercel‑provided nameservers ns1.vercel-dns.com and ns2.vercel-dns.com, and the registrar entry lists Vercel Inc. as the sponsoring registrar. An HTTPS endpoint was secured with a Let’s Encrypt R12 certificate, and the server advertised HTTP Strict Transport Security (HSTS). The web server returned HTTP status code 451, indicating legal restrictions, and the page title captured by crawlers reads “Xaman Wallet Desktop – The Leading Self‑Custody Wallet To Claim Glacier Drop For XRPL”, directly referencing the Xaman brand and a fictitious “Glacier Drop” promotion.
Threat intelligence sources have flagged the domain in one AlienVault OTX pulse and it appears on two public blocklists. Both PhishDestroy and ScamSniffer have added the domain to their block lists, confirming its classification as a crypto‑related scam. VirusTotal scanned the site and 12 of 95 security vendors reported malicious activity, reinforcing the suspicion of malicious intent. The combination of brand‑impersonating page title, crypto‑scam label, and multiple vendor detections indicates a coordinated attempt to lure Xaman users into a fraudulent wallet download or credential harvest. Current observations show the domain is taken offline, which may be a temporary takedown or a shift to another hosting location.
No further content has been captured, and the exact payload or credential‑capture mechanism remains unknown. Defenders should continue to monitor DNS queries for the IP address 64.29.17.1 and the Vercel nameservers, update endpoint protection to block the domain, and add the associated hash of the SSL certificate to block lists.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
9 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Inaccessible → Accessible
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
2 technologies identifiées avec une forte confiance
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif