Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 2 outgoing records; the latest is dated . The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
xmrwallet[.]app
“XMR Wallet Online | Secure Monero Wallet”
xmrwallet.app — असत्यापित. घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 7/91 (alphaMountain.ai, CRDF, ESET, Forcepoint ThreatSeeker, Fortinet); URLQuery 4 alerts; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. रजिस्ट्रार: Tucows.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, xmrwallet.app, was registered on February 21, 2026 through Tucows Domains Inc. and is presently active. It presents the page title "XMR Wallet Online | Secure Monero Wallet," indicating an attempt to masquerade as a legitimate Monero wallet service. The threat is classified as a crypto drainer and assigned a high risk rating. The site responds with an HTTP 307 temporary redirect, suggesting a redirection stage before delivering payload. SSL analysis shows a certificate labeled R12, issued for the domain, and the site enforces HTTP Strict Transport Security (HSTS). Infrastructure fingerprints reveal deployment on Vercel, and DNS resolution points to the Amazon‑owned address 216.198.79.65, belonging to AS16509. The three nameservers – 1-you.njalla.no, 2-can.njalla.in, and 3-get.njalla.fo – are hosted by the njalla service. VirusTotal has recorded a single detection out of 95 scanned security vendors, indicating limited but present antivirus awareness. The domain appears on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its malicious reputation. No additional intelligence on the page content has been released, so the exact mechanisms used to drain cryptocurrency remain unverified. Defenders should block DNS resolution to 216.198.79.65 and add the domain to web filtering rules. Monitoring for HTTP 307 responses from this host can aid early detection. Given the use of Vercel and the njalla nameserver set, threat‑hunting queries targeting similar infrastructure may uncover related campaigns. Continuous re‑scanning with VirusTotal and updating blocklist signatures are recommended to capture any emerging detections.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | xmrwallet.app |
malicious | Sinkholed |
| DNS4EU | xmrwallet.app |
malicious | Sinkholed |
| Hagezi Threat Feed | www.xmrwallet.app |
malicious | Sinkholed |
| DNS4EU | www.xmrwallet.app |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
दुरुपयोग रिपोर्ट इतिहास · 2 stored reports over 80 days · click to expand
-
Report #1 ICANN CC Feb 19, 2026 · 00:46 UTCESCALATION #2 (-1h active): Phishing - xmrwallet[.]appdomainabuse@tucows.com registry-abuse-support@google.com compliance@icann.org
-
Report #3 ICANN CC 1895h still active May 9, 2026 · 06:29 UTCESCALATION #3 (1895h active): Phishing - xmrwallet[.]appdomainabuse@tucows.com registry-abuse-support@google.com compliance@icann.org
तकनीकें · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of xmrwallet.app · checked Mar 2, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-1771461984-xmrwallet.app Recipient: domainabuse@tucows.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।