xamansolo[.]com
“Xaman × Sologenic — XRPL Ecosystem Airdrop · $SOLO LP Allocation”
Зведення доказів
The domain xamansolo.com was identified as a high-risk brand impersonation threat targeting users of the XRP Ledger (XRPL) ecosystem. Analysis confirms this domain facilitated an airdrop scam, specifically impersonating the Xaman wallet and Sologenic ($SOLO) token allocation program. The page title, 'Xaman × Sologenic — XRPL Ecosystem Airdrop · $SOLO LP Allocation,' directly mimics legitimate promotional campaigns to deceive victims into interacting with malicious smart contracts or disclosing private keys. The domain is currently offline, though prior activity remains a verified risk. Infrastructure analysis reveals xamansolo.com was registered on June 3, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with abuse complaints. The domain resolved to the IP address 188.114.97.3, a Cloudflare-protected endpoint, and was detected by 14 of 95 security vendors on VirusTotal. It appeared on four independent security blocklists and was actively blocked by multiple wallet security tools, including MetaMask’s built-in phishing detection and ScamSniffer’s transaction monitoring systems. Technologies detected on the domain included HTTP/3, HSTS, and Cloudflare Browser Insights, suggesting an attempt to mimic legitimate, high-security platforms. Given the domain’s current offline status, immediate interaction risks are reduced, though historical exposure remains a concern. Users who previously visited or engaged with this domain should revoke any connected wallet permissions, rotate private keys, and monitor accounts for unauthorized transactions. Organizations are advised to update blocklists with the domain and IP address (188.114.97.3) to prevent future access. Security teams should prioritize monitoring for similar impersonation attempts targeting XRPL or other blockchain ecosystems, particularly those leveraging Cloudflare-protected infrastructure and registrar patterns consistent with NICENIC INTERNATIONAL GROUP CO., LIMITED.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
7 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
VirusTotal
11 → 14
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 4 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога