xamanxrpl[.]com
“Xaman XRPL Loyalty & RLUSD Allocation Program”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy identifies xamanxrpl.com as a high-risk crypto drainer phishing domain, currently taken offline but still posing a significant threat to cryptocurrency users. The site impersonates the legitimate Xaman XRPL platform, attempting to trick users into connecting their wallets and draining funds. With an elevated risk level, this domain was specifically designed to steal XRP and other digital assets through fake loyalty reward schemes.
Technical analysis reveals several concerning indicators: the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and created on May 26, 2026, suggesting a recently established malicious operation. It resolves to IP address 188.114.97.3 and uses a Let's Encrypt SSL certificate (E7), which provides a false sense of security. Despite only 1 out of 95 security vendors on VirusTotal flagging the domain, it appears on 3 security blocklists, indicating partial recognition of its malicious nature. The page title "Xaman XRPL Loyalty" reinforces the deceptive branding designed to lure victims.
Users who encounter xamanxrpl.com should never connect their cryptocurrency wallets or enter any sensitive information. Since this is a crypto drainer, the primary risk is unauthorized transfer of funds from connected wallets. Always verify official URLs directly from the Xaman XRPL application or official website. If you have already interacted with this site, immediately revoke any wallet permissions and transfer assets to a new wallet. Report the domain to relevant security platforms and monitor your accounts for suspicious activity.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 4 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога