Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,757Total Detected
144,291Taken Down
91.6%Kill Rate
93.4%VT Coverage
45,576Abuse Reports
Overview Jun 268,229 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of ethereumoluxapp.com
ethereumoluxapp.com
19 VTTaken Down
Screenshot of ethereumoluxplatformapp.com
ethereumoluxplatformapp.com
19 VTTaken Down
Screenshot of ex-odus.framer.media
ex-odus.framer.media
19 VTTaken Down
Screenshot of exodus-start.io
exodus-start.io
19 VTTaken Down
Screenshot of faceit.en-victoryhub.com
faceit.en-victoryhub.com
19 VTTaken Down
Screenshot of faceit.join-victory-hub.com
faceit.join-victory-hub.com
19 VTTaken Down
Screenshot of fastpromo.vip
fastpromo.vip
19 VTTaken Down
Screenshot of flare.shafultonb.com
flare.shafultonb.com
19 VTTaken Down
Screenshot of g-gamb.cc
g-gamb.cc
19 VTTaken Down
Screenshot of g62t.xyz
g62t.xyz
19 VTTaken Down
Screenshot of geminiiiidlugeeeenn8.godaddysites.com
geminiiiidlugeeeenn8.godaddysites.com
19 VTTaken Down
Screenshot of genesisbola.biz
genesisbola.biz
19 VTTaken Down
Screenshot of getdiscount.vip
getdiscount.vip
19 VTTaken Down
Screenshot of glowspin.digital
glowspin.digital
19 VTTaken Down
Screenshot of gmxdenetdienst.weebly.com
gmxdenetdienst.weebly.com
19 VTTaken Down
Screenshot of gmxnetdedienst.weebly.com
gmxnetdedienst.weebly.com
19 VT
Screenshot of gopay13.isvn.top
gopay13.isvn.top
19 VTTaken Down
Screenshot of gopay24.isvn.top
gopay24.isvn.top
19 VTTaken Down
Screenshot of gopay36.isvn.top
gopay36.isvn.top
19 VTTaken Down
Screenshot of gopay36.vnyn.top
gopay36.vnyn.top
19 VTTaken Down
Screenshot of gopay48.ejcx.top
gopay48.ejcx.top
19 VT
Screenshot of gopay7.vkgh.top
gopay7.vkgh.top
19 VTTaken Down
Screenshot of gopay73.vnyn.top
gopay73.vnyn.top
19 VTTaken Down
Screenshot of grounded-course-230298.framer.app
grounded-course-230298.framer.app
19 VTTaken Down
Screenshot of gtgamb.cc
gtgamb.cc
19 VTTaken Down
Screenshot of heleket.io
heleket.io
19 VTTaken Down
Screenshot of hideeorlinofficialjob.com
hideeorlinofficialjob.com
19 VTTaken Down
Screenshot of housein.digital
housein.digital
19 VT
Screenshot of ibleaputi.digital
ibleaputi.digital
19 VTTaken Down
Screenshot of iddxupdate.live
iddxupdate.live
19 VT
Screenshot of identifiant-ledger.com
identifiant-ledger.com
19 VTTaken Down
Screenshot of incredible-staple-338196.framer.app
incredible-staple-338196.framer.app
19 VTTaken Down
Screenshot of innovvatifworrrkid.com
innovvatifworrrkid.com
19 VTTaken Down
Screenshot of interactive-colleagues-062202.framer.app
interactive-colleagues-062202.framer.app
19 VTTaken Down
Screenshot of iohwauldgrndiawodibaobfwf.netlify.app
iohwauldgrndiawodibaobfwf.netlify.app
19 VTTaken Down
Screenshot of isywetwqky.yoga
isywetwqky.yoga
19 VTTaken Down
Screenshot of j235j.xyz
j235j.xyz
19 VTTaken Down
Screenshot of kinietiq.xyz
kinietiq.xyz
19 VTTaken Down
Screenshot of kkuiiicnn110giin.godaddysites.com
kkuiiicnn110giin.godaddysites.com
19 VTTaken Down
Screenshot of korea-ripple.net
korea-ripple.net
19 VT
Screenshot of kucunlogn.webflow.io
kucunlogn.webflow.io
19 VTTaken Down
Screenshot of ledger-live-docs.m-teach.com
ledger-live-docs.m-teach.com
19 VTTaken Down
Screenshot of ledgers-live.io
ledgers-live.io
19 VTTaken Down
Screenshot of linkfly.vip
linkfly.vip
19 VTTaken Down
Screenshot of m29x.xyz
m29x.xyz
19 VTTaken Down
Screenshot of maileasyaccess.com
maileasyaccess.com
19 VTTaken Down
Screenshot of methasin43-massklogg.godaddysites.com
methasin43-massklogg.godaddysites.com
19 VTTaken Down
Screenshot of metimaasklogiez.godaddysites.com
metimaasklogiez.godaddysites.com
19 VTTaken Down
Screenshot of miiiiccrroofdsofttyyresghnmnjh.weebly.com
miiiiccrroofdsofttyyresghnmnjh.weebly.com
19 VTTaken Down
Screenshot of mitrarekan.com
mitrarekan.com
19 VTTaken Down
Screenshot of mob.authez.top
mob.authez.top
19 VTTaken Down
Screenshot of mondroitaide.net
mondroitaide.net
19 VTTaken Down
Screenshot of movelistrade92.net
movelistrade92.net
19 VTTaken Down
Screenshot of mtamasckvloglz.gitbook.io
mtamasckvloglz.gitbook.io
19 VTTaken Down
Screenshot of mysteryclaims6347-live.vercel.app
mysteryclaims6347-live.vercel.app
19 VTTaken DownAngel Drainer
Screenshot of n3dcj-maaaa-aaaad-qal3q-cai.raw.ic0.app
n3dcj-maaaa-aaaad-qal3q-cai.raw.ic0.app
19 VTTaken Down
Screenshot of navernid.pythonanywhere.com
navernid.pythonanywhere.com
19 VTTaken Down
Screenshot of neonwin.cc
neonwin.cc
19 VTTaken Down
Screenshot of net-coin.framer.wiki
net-coin.framer.wiki
19 VTTaken Down
Screenshot of netflex-hub.netlify.app
netflex-hub.netlify.app
19 VTTaken Down
« Prev ... 7 8 9 10 11 12 13 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.