xamanwallet[.]money
Category: Suspicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xamanwallet[.]money
The domain xamanwallet[.]money appears to present a login or sign-up page styled to resemble the social platform X, based on the visible branding, page title, and metadata reading “X. It’s what’s happening / X.” However, the domain name itself references “Xaman Wallet,” which is commonly associated with the XRP Ledger wallet ecosystem rather than the X social-media brand. That mismatch suggests the site may not be an official destination for either service.
Available page elements and referenced domains indicate connections to Xaman-related properties such as xaman.app, xumm.app, and xrpl-labs.com, alongside mainstream platforms like Apple, Google Play, GitHub, LinkedIn, YouTube, and X. Based on the domain name, hosting setup, and screenshot, this appears to be a newly created web property that may be attempting to attract users interested in cryptocurrency wallet services while displaying branding associated with a different well-known platform.
Safety Assessment for xamanwallet[.]money
Scan results show mixed signals at the time of this scan. The domain was flagged by 3 out of 92 security engines, while major blacklist checks included in the scan were clean. The malware scan did not identify malicious files, but the site is extremely new at just 1 day old, has no established traffic ranking, and uses a domain name that does not align with the branding shown on the page.
The visible content closely resembles the login page of X, yet the domain is xamanwallet[.]money rather than an official X-related domain. That kind of branding mismatch may indicate a look-alike or impersonation attempt, especially when combined with a newly registered domain and a request for account interaction. Although no confirmed malware payload was detected in the provided scan data, users should treat credential-entry or wallet-related interactions on such a site with caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate and is served through Cloudflare infrastructure, with the web server identified as cloudflare envoy and nameservers hosted on Cloudflare. The resolved IP address is 104.21.49.92, and the scan places the hosting location in Toronto, Canada. TLS is present, which helps encrypt traffic in transit, but certificate validity alone does not verify operator legitimacy.
From a domain-security perspective, the registration is very recent, DNSSEC appears to be unsigned, and the registrar is NICENIC INTERNATIONAL GROUP CO., LIMITED. The combination of a very young domain, absent reputation history, and branding inconsistency is a more meaningful concern than the basic hosting setup. No malicious files or iframes were identified in the supplied scan, but the overall infrastructure profile is consistent with a newly deployed site.
Share your experience with this website. Was it safe? Did you encounter any issues?