Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 2 outgoing records; the latest is dated . The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
xmrwallet[.]app
“XMR Wallet Online | Secure Monero Wallet”
xmrwallet.app — 未验证. 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 7/91 (alphaMountain.ai, CRDF, ESET, Forcepoint ThreatSeeker, Fortinet); URLQuery 4 alerts; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, xmrwallet.app, was registered on February 21, 2026 through Tucows Domains Inc. and is presently active. It presents the page title "XMR Wallet Online | Secure Monero Wallet," indicating an attempt to masquerade as a legitimate Monero wallet service. The threat is classified as a crypto drainer and assigned a high risk rating. The site responds with an HTTP 307 temporary redirect, suggesting a redirection stage before delivering payload. SSL analysis shows a certificate labeled R12, issued for the domain, and the site enforces HTTP Strict Transport Security (HSTS). Infrastructure fingerprints reveal deployment on Vercel, and DNS resolution points to the Amazon‑owned address 216.198.79.65, belonging to AS16509. The three nameservers – 1-you.njalla.no, 2-can.njalla.in, and 3-get.njalla.fo – are hosted by the njalla service. VirusTotal has recorded a single detection out of 95 scanned security vendors, indicating limited but present antivirus awareness. The domain appears on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its malicious reputation. No additional intelligence on the page content has been released, so the exact mechanisms used to drain cryptocurrency remain unverified. Defenders should block DNS resolution to 216.198.79.65 and add the domain to web filtering rules. Monitoring for HTTP 307 responses from this host can aid early detection. Given the use of Vercel and the njalla nameserver set, threat‑hunting queries targeting similar infrastructure may uncover related campaigns. Continuous re‑scanning with VirusTotal and updating blocklist signatures are recommended to capture any emerging detections.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | xmrwallet.app |
malicious | Sinkholed |
| DNS4EU | xmrwallet.app |
malicious | Sinkholed |
| Hagezi Threat Feed | www.xmrwallet.app |
malicious | Sinkholed |
| DNS4EU | www.xmrwallet.app |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
滥用举报历史 · 2 stored reports over 80 days · click to expand
-
Report #1 ICANN CC Feb 19, 2026 · 00:46 UTCESCALATION #2 (-1h active): Phishing - xmrwallet[.]appdomainabuse@tucows.com registry-abuse-support@google.com compliance@icann.org
-
Report #3 ICANN CC 1895h still active May 9, 2026 · 06:29 UTCESCALATION #3 (1895h active): Phishing - xmrwallet[.]appdomainabuse@tucows.com registry-abuse-support@google.com compliance@icann.org
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of xmrwallet.app · checked Mar 2, 2026
证据与外部报告
PD-1771461984-xmrwallet.app Recipient: domainabuse@tucows.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。