Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 2. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Etki alanı güvenliği ve tehdit istihbaratı

xmrwallet[.]biz

“Best Monero Wallet (XMR) - Send & Receive Monero Securely”

Tehdit kararı Yüksek 56/100 kanıt puanı
Kullanılabilirlik İçerik kullanılamıyor En son gözlemde içerik mevcut değildi
VirusTotal algılamaları: 2/95 Marka kimliğine bürünme: Ethereum
26.02.2026 Ethereum 2 Reports Sent
Rapor özeti

xmrwallet.biz — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Ethereum; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 2/95 (Gridinsoft, Seclookup); PhishDestroy score 56/100. Kayıt kuruluşu: Web Commerce Communica….

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Kanıt özeti
YÜKSEK
Ref
A989CAF2
Puan
56/100

On 21 February 2026 the domain xmrwallet.biz was registered through Web Commerce Communications Limited. The authoritative name resolution points to the single IPv4 address 190.115.31.40, which is announced by AS59692 (IQWeb FZ‑LLC) and geolocated to Belize. The host presents an SSL certificate with an R13 rating, indicating a low trust level. Automated scanning on VirusTotal shows that two of ninety‑five security vendors flagged the domain as malicious, providing an early indication of compromise.

The site is listed on one public security blocklist and has been actively blocked by the PhishDestroy filtering service. The observed page title, “Best Monero Wallet (XMR) – Send & Receive Monero Securely”, suggests that the domain was being used to lure victims into interacting with a purported Monero wallet service. Technology fingerprints extracted from the live response include PHP, jQuery, HTTP Strict Transport Security (HSTS) and the DDoS‑Guard protection layer, a combination frequently observed in malicious crypto‑drainer infrastructure. No additional content analysis is available because the service was taken offline prior to this assessment.

Current evidence confirms the presence of a crypto‑drainer operation associated with xmrwallet.biz, but detailed tactics such as credential harvesting, transaction redirection, or malware delivery have not been observed. Consequently, the precise victim interaction flow remains uncertain. Defenders should continue to enforce domain‑level blocking for xmrwallet.biz, include the associated IP address 190.115.31.40 in network‑level deny lists, and monitor for any future re‑registration or reuse of the same hosting provider. Ongoing threat‑intel feeds should be consulted for updates, and any detection of similar PHP‑based wallet front‑ends should be treated with heightened scrutiny given the observed pattern.

VirusTotal
VirusTotal
2 det.
URLScan
URLScan
TLS sertifikası
Süresi dolmuş veya doğrulanmamış
Yaş
6 mo
Gözlemlenen durum
İçerik kullanılamıyor 502
PhishDestroy
DestroyList
Listede
Reports Sent
2
Veri kapsamı VirusTotal 2 / 95 URLQuery kontrol edilmedi PhishStats kontrol edilmedi OTX no community references CF Radarı scan completed URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri kontrol edilmedi TLS Süresi dolmuş veya doğrulanmamış WHOIS 6 mo old Ekran görüntüsü harici görüntü Yönlendirme zinciri araştırılmadı

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
17/17
Initial Abuse Report (#1)
Sent to 3 abuse contacts at Web Commerce Communications Limited with forensic evidence
compliance_abuse@webnic.ccabuse@registry.godaddycompliance@icann.org
21.02.2026
ICANN Escalation #2
Escalation #2 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
compliance_abuse@webnic.ccabuse@registry.godaddycompliance@icann.org
22.02.2026
2 Reports Filed
2 report records were stored over 177 days; current observed status: İçerik kullanılamıyor

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Sayfa başlığı
Best Monero Wallet (XMR) - Send & Receive Monero Securely
Impersonates
Ethereum
TLS sertifikası
Süresi dolmuş veya doğrulanmamış · Düzenleyen R13

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Sunucu / ASN ddos-guard · AS59692 IQWEB IQWeb FZ-LLC, AE
IP itibarı abuse score 0/100 0 reports checked 14.06.2026
Kayıt kuruluşu Web Commerce Communica… MY(MY)
IP adresi 190.115.31.40 BZ
Coğrafi konumBZ Belize City, BZ
AS59692 · IQWeb FZ-LLC
KayıtOluşturuldu 21.02.2026 (177d)
HTTP Durumu502 Error
İlk erişilemezliğe kadar geçen süre 10 days
Neyi ölçüyoruz Depolanan ilk kötüye kullanım raporundan içeriğin kullanılamadığına dair ilk gözleme kadar geçen süre. Bu, nedeni belirlemez.
Minimum notice count 2 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Her raporun içeriği Saklanan giden rapor kayıtları, satıcı kararları, kayıt verileri, barındırma ayrıntıları, sınıflandırmalar veya ekran görüntüleri gibi o sırada mevcut olan kanıtlara referans verebilir. Bu sayfa, teslim edilen yükün, alındığının, onaylandığının veya alıcının yaptığı eylemin tam olarak ne olduğu konusunda bir sonuç çıkarmaz.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi26.02.2026
DOM Analysisanalyzed 29.07.2026score 56/1001 brand signal
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Case ID
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Kötüye Kullanım Bildirimi Geçmişi · 2 stored reports over 2 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
2 abuse reports filed over 177 days — latest observed status: İçerik kullanılamıyor
The records name Web Commerce Communications Limited as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
2
reports
177
days
ICANN CC
  1. Report #1 ICANN CC 37h still active Feb 21, 2026 · 06:05 UTC
    ESCALATION #2 (37h active): Phishing - xmrwallet[.]biz
    compliance_abuse@webnic.cc abuse@registry.godaddy compliance@icann.org
  2. Report #2 ICANN CC 28h still active Feb 22, 2026 · 13:45 UTC
    ESCALATION #3 (28h active): Phishing - xmrwallet[.]biz
    compliance_abuse@webnic.cc abuse@registry.godaddy compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Teknolojiler · 4 identified
PHP
Programming languages

Server-side scripting language designed for web development.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

HSTS
Güvenlik

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

DDoS-Guard
Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

2 / 95 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed
Gridinsoft
Seclookup

Kanıtlar ve Dış Raporlar

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-1771653923-xmrwallet.biz Recipient: compliance_abuse@webnic.cc
URLScan evidence VirusTotal evidence

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/xmrwallet.biz"
  title="PhishDestroy threat report for xmrwallet.biz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.