Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
xamanpro[.]app
“Xaman | Xaman Pro - XRP Ledger Wallet”
Зведення доказів
This domain, xamanpro.app, is flagged as a high-risk brand impersonation resource specifically targeting Ledger cryptocurrency wallet users. Analysis indicates the site masquerades as a legitimate XRP Ledger wallet interface, presenting itself under the page title 'Xaman | Xaman Pro - XRP Ledger Wallet.' The objective appears to be the deployment of crypto drainer malware, designed to siphon digital assets from unsuspecting victims by mimicking trusted wallet software. No direct evidence of a specific drainer kit was observed, but the combination of brand impersonation and wallet-themed content strongly suggests malicious intent aligned with cryptocurrency theft operations. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Hosting Concepts B.V. d/b/a Registrar.eu, a registrar commonly associated with both legitimate and malicious registrations. The domain resolves to the IP address 92.113.23.211, which is hosted on infrastructure utilizing Hostinger CDN and HTTP/3 protocols. Detection metrics indicate broad recognition of the threat, with 13 out of 95 security vendors on VirusTotal flagging the domain as malicious. Additionally, the domain appears on three distinct security blocklists, and MetaMask, SEAL, and PhishDestroy have implemented active blocks. Gridinsoft assigns a trust score of 0 out of 100, further corroborating the high-risk assessment. Google Safe Browsing status was not explicitly provided, but the cumulative detection data suggests likely inclusion. As of the latest assessment, xamanpro.app has been taken offline, reducing immediate exposure to potential victims. However, the domain remains registered and could be reactivated or repurposed for future malicious campaigns. Users who may have interacted with the site are advised to revoke any connected wallet permissions, monitor transaction histories for unauthorized activity, and verify the authenticity of any cryptocurrency wallet software through official channels. The infrastructure and registration details suggest the threat actor may retain control of the domain, warranting continued vigilance from security teams and end-users alike.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260204-32E98D- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Acceptable Use Policy (AUP): The domain xamanpro.app is engaged in phishing activities, which directly contravenes the AUP's prohibition against illegal activities and fraud.
Terms of Service (TOS): The ongoing use of this domain for deceptive practices constitutes a violation of the TOS, allowing for immediate suspension or termination of services.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable as phishing schemes often involve unauthorized data access.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, which is relevant to the activities conducted by xamanpro.app.
Anti-Phishing Consumer Protection Act: This act aims to combat phishing and other fraudulent online practices, making the operation of xamanpro.app unlawful.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to liability under applicable laws and regulations. Non-compliance could result in legal repercussions and damage to your reputation.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | xamanpro.app |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
VirusTotal
8 → 11
-
VirusTotal
8 → 13
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of xamanpro.app · checked Jun 27, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога