Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
xamanpro[.]app
“Xaman | Xaman Pro - XRP Ledger Wallet”
证据摘要
This domain, xamanpro.app, is flagged as a high-risk brand impersonation resource specifically targeting Ledger cryptocurrency wallet users. Analysis indicates the site masquerades as a legitimate XRP Ledger wallet interface, presenting itself under the page title 'Xaman | Xaman Pro - XRP Ledger Wallet.' The objective appears to be the deployment of crypto drainer malware, designed to siphon digital assets from unsuspecting victims by mimicking trusted wallet software. No direct evidence of a specific drainer kit was observed, but the combination of brand impersonation and wallet-themed content strongly suggests malicious intent aligned with cryptocurrency theft operations. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Hosting Concepts B.V. d/b/a Registrar.eu, a registrar commonly associated with both legitimate and malicious registrations. The domain resolves to the IP address 92.113.23.211, which is hosted on infrastructure utilizing Hostinger CDN and HTTP/3 protocols. Detection metrics indicate broad recognition of the threat, with 13 out of 95 security vendors on VirusTotal flagging the domain as malicious. Additionally, the domain appears on three distinct security blocklists, and MetaMask, SEAL, and PhishDestroy have implemented active blocks. Gridinsoft assigns a trust score of 0 out of 100, further corroborating the high-risk assessment. Google Safe Browsing status was not explicitly provided, but the cumulative detection data suggests likely inclusion. As of the latest assessment, xamanpro.app has been taken offline, reducing immediate exposure to potential victims. However, the domain remains registered and could be reactivated or repurposed for future malicious campaigns. Users who may have interacted with the site are advised to revoke any connected wallet permissions, monitor transaction histories for unauthorized activity, and verify the authenticity of any cryptocurrency wallet software through official channels. The infrastructure and registration details suggest the threat actor may retain control of the domain, warranting continued vigilance from security teams and end-users alike.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260204-32E98D- PDF 文件
- PDF 证据
完整证据文本
Acceptable Use Policy (AUP): The domain xamanpro.app is engaged in phishing activities, which directly contravenes the AUP's prohibition against illegal activities and fraud.
Terms of Service (TOS): The ongoing use of this domain for deceptive practices constitutes a violation of the TOS, allowing for immediate suspension or termination of services.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable as phishing schemes often involve unauthorized data access.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, which is relevant to the activities conducted by xamanpro.app.
Anti-Phishing Consumer Protection Act: This act aims to combat phishing and other fraudulent online practices, making the operation of xamanpro.app unlawful.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to liability under applicable laws and regulations. Non-compliance could result in legal repercussions and damage to your reputation.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | xamanpro.app |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
-
VirusTotal
8 → 11
-
VirusTotal
8 → 13
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of xamanpro.app · checked Jun 27, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控