सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 6। किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 2। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

dao-xaman[.]app

धमकी भरा फैसला गंभीर 85/100 साक्ष्य स्कोर
उपलब्धता पहुंच योग्य · पहुंच प्रतिबंधित पहुंच योग्य प्रतिक्रिया; पृष्ठ सामग्री सत्यापित नहीं थी
वायरस का कुल पता लगाना: 6/91 Spamhaus DBL: DBL_PHISH संग्रहीत ब्लॉकलिस्ट मिलान: 2 घोटाले का प्रकार: Generic Phishing अंतिम ज्ञात सक्रिय
15/06/2026 CDN
रिपोर्ट सारांश

dao-xaman.app — पहुंच योग्य · पहुंच प्रतिबंधित (HTTP 403). घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 6/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. रजिस्ट्रार: NiceNIC.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
64B3FA97
स्कोर
85/100

The domain dao-xaman.app has been identified as a generic phishing threat, specifically a crypto drainer and brand impersonation site targeting Xaman (formerly Xumm) users. This malicious domain was designed to trick victims into believing they were interacting with the legitimate Xaman platform, a popular wallet for the XRP Ledger. The threat actors behind this operation likely deployed a drainer kit to steal cryptocurrency assets upon user interaction.

Technical indicators reveal that dao-xaman.app was created on May 29, 2026, and registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain resolves to IP address 188.114.97.3 and uses an SSL certificate issued by Let's Encrypt (identified as YE2). VirusTotal analysis shows that 3 out of 95 security vendors flagged this domain as malicious. Additionally, the domain appears on three security blocklists, and its current status is offline as it has been taken down.

As of now, dao-xaman.app is offline, indicating that response actions have been taken to mitigate the threat. However, users should remain vigilant as similar domains may reappear. It is strongly recommended to avoid interacting with any unsolicited communications referencing Xaman or crypto wallets without verifying the official domain. PhishDestroy advises users to enable two-factor authentication, use hardware wallets, and report any suspicious domains to security authorities.

VirusTotal
VirusTotal
6 det.
TLS प्रमाणपत्र
Let's Encrypt / YE2 9d
आयु
3 mo New
देखी गई स्थिति
पहुंच योग्य · पहुंच प्रतिबंधित 403
PhishDestroy
विनाश सूची
सूचीबद्ध
डेटा कवरेज VirusTotal 6 / 91 यूआरएलक्वेरी जाँच नहीं की गई फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार no data URLScan capture not submitted URLScan verdict निष्कर्ष उपलब्ध नहीं डीएनएस ब्लॉक जाँच नहीं की गई TLS valid certificate, 9d कौन है 3 mo old स्क्रीनशॉट कैद नहीं हुआ चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
9/11

सार्वजनिक ब्लॉकलिस्ट स्थिति

डोमेन इंटेलिजेंस

डोमेन
सर्वर / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
रजिस्ट्रार NiceNIC RU(RU) PhishDestroy Investigation
IP पता 188.114.97.3 CDN
भौगोलिक स्थानCA Toronto, CA
नेटवर्कAS13335 · CloudFlare, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
पंजीकरणनिर्मित 29/05/2026 (80d · New) Expires 29/05/2027
HTTP स्थिति403 Forbidden
Elapsed Since First Report 50 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: पहुंच योग्य · पहुंच प्रतिबंधित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला15/06/2026
TLS Fingerprint
TLS Observationvalid from 29/05/2026scanned 13/06/2026
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।

Latest Classified Outcome 2026-08-17 02:41:32 UTC

Primary outcome Provider block observed reason: Cloudflare anti-phishing block 95% confidence
Attribution Cloudflare mechanism: Phishing Interstitial source: Current Http Probe
Evidence layers Availability: Provider blocked Content: Provider blocked DNS: Resolved Registration: Active
Latest HTTP observation Provider block observed Cloudflare anti-phishing block Cloudflare Phishing Interstitial 95% provider marker verified 2026-08-17 02:41:32 UTC
RDAP registration सक्रिय NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibited expires 2027-05-29 15:09:03 UTC checked 2026-08-05 19:11:26 UTC
Observed timeline last reachable: 2026-08-16 22:15:11 UTC current episode first observed: 2026-08-17 02:41:32 UTC observed RIP window: 2026-08-16 22:15:11 UTC → 2026-08-17 02:41:32 UTC · 4.44h midpoint estimate ≈ 2026-08-17 00:28:21 UTC · precision high · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

6 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
Bfore.Ai PreCrime
CRDF
Fortinet
Gridinsoft
SOCRadar

साक्ष्य और बाहरी रिपोर्टें

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/dao-xaman.app"
  title="PhishDestroy threat report for dao-xaman.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।