Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,764Total Detected
144,291Taken Down
91.6%Kill Rate
93.4%VT Coverage
45,581Abuse Reports
Overview Jun 268,236 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of nobira-xel.net
nobira-xel.net
19 VTTaken Down
Screenshot of nowcharge.cfd
nowcharge.cfd
19 VTTaken Down
Screenshot of nstutqucbooks.weebly.com
nstutqucbooks.weebly.com
19 VTTaken Down
Screenshot of nusewin.cc
nusewin.cc
19 VT
Screenshot of ooooo-oooo-oooo.surge.sh
ooooo-oooo-oooo.surge.sh
19 VTTaken Down
Screenshot of orange-group.back2buzz.eu
orange-group.back2buzz.eu
19 VTTaken Down
Screenshot of ox0z3x.top
ox0z3x.top
19 VTTaken Down
Screenshot of phantom-wallett.blogspot.hk
phantom-wallett.blogspot.hk
19 VTTaken Down
Screenshot of podologuesaintpierre.fr
podologuesaintpierre.fr
19 VTTaken Down
Screenshot of polvestionpro.pl
polvestionpro.pl
19 VTTaken Down
Screenshot of post-luxo.com
post-luxo.com
19 VTTaken Down
Screenshot of promobhd.webcindario.com
promobhd.webcindario.com
19 VTTaken Down
Screenshot of protocol.uniswap-staging.org
protocol.uniswap-staging.org
19 VT
Screenshot of quantumswiftforumai.top
quantumswiftforumai.top
19 VTTaken Down
Screenshot of quickbee.vip
quickbee.vip
19 VTTaken Down
Screenshot of raydiumsolutions.xyz
raydiumsolutions.xyz
19 VTTaken DownSolana Drainer
Screenshot of receptive-purpose-551959.framer.app
receptive-purpose-551959.framer.app
19 VTTaken Down
Screenshot of recov-trwstvvallet.com
recov-trwstvvallet.com
19 VTTaken Down
Screenshot of ruwahotekoff.digital
ruwahotekoff.digital
19 VT
Screenshot of sampaworks.info
sampaworks.info
19 VTTaken Down
Screenshot of sdktek.sbs
sdktek.sbs
19 VTTaken Down
Screenshot of seacure-learn-metamask-login.typedream.app
seacure-learn-metamask-login.typedream.app
19 VT
Screenshot of seeker-mobile.net
seeker-mobile.net
19 VTSolana Drainer
Screenshot of shawww55.weebly.com
shawww55.weebly.com
19 VTTaken Down
Screenshot of shibac.vip
shibac.vip
19 VTTaken Down
Screenshot of site-2xyv2b8yf.godaddysites.com
site-2xyv2b8yf.godaddysites.com
19 VTTaken Down
Screenshot of soleryxastrael88.com
soleryxastrael88.com
19 VTTaken Down
Screenshot of sso--uphoold--cdn-autth-x.typedream.app
sso--uphoold--cdn-autth-x.typedream.app
19 VT
Screenshot of stakingsreward.one
stakingsreward.one
19 VTTaken Down
Screenshot of starsupdate.live
starsupdate.live
19 VT
Screenshot of startgamb.cc
startgamb.cc
19 VTTaken Down
Screenshot of store.workshop-glock18.cc
store.workshop-glock18.cc
19 VTTaken Down
Screenshot of sulvix-850v.com
sulvix-850v.com
19 VTTaken Down
Screenshot of symphonious-cannoli-76b929.netlify.app
symphonious-cannoli-76b929.netlify.app
19 VTTaken DownWallet Connect Abuse
Screenshot of t-mobile.awpqk.cc
t-mobile.awpqk.cc
19 VTTaken Down
Screenshot of t-mobile.ftqrt.cc
t-mobile.ftqrt.cc
19 VTTaken Down
Screenshot of t-mobile.ftrjd.cc
t-mobile.ftrjd.cc
19 VTTaken Down
Screenshot of t-mobile.gtfic.cc
t-mobile.gtfic.cc
19 VTTaken Down
Screenshot of t-mobile.hztkv.cc
t-mobile.hztkv.cc
19 VTTaken Down
Screenshot of t-mobile.ieulc.cc
t-mobile.ieulc.cc
19 VTTaken Down
Screenshot of t-mobile.miqr.cc
t-mobile.miqr.cc
19 VTTaken Down
Screenshot of t-mobile.oflxe.cc
t-mobile.oflxe.cc
19 VTTaken Down
Screenshot of t-mobile.osawe.cc
t-mobile.osawe.cc
19 VTTaken Down
Screenshot of t-mobile.qarhj.cc
t-mobile.qarhj.cc
19 VTTaken Down
Screenshot of t-mobile.steig.cc
t-mobile.steig.cc
19 VTTaken Down
Screenshot of t-mobile.tiondgk.cc
t-mobile.tiondgk.cc
19 VTTaken Down
Screenshot of t-mobile.tjfdy.cc
t-mobile.tjfdy.cc
19 VTTaken Down
Screenshot of t-mobile.tlpsf.cc
t-mobile.tlpsf.cc
19 VTTaken Down
Screenshot of t-mobile.vytpw.cc
t-mobile.vytpw.cc
19 VTTaken Down
Screenshot of t-mobile.yfdje.cc
t-mobile.yfdje.cc
19 VTTaken Down
Screenshot of testtri.live
testtri.live
19 VTTaken Down
Screenshot of theexecutiveofficialjob.com
theexecutiveofficialjob.com
19 VTTaken Down
Screenshot of thunderous-sorbet-780abf.netlify.app
thunderous-sorbet-780abf.netlify.app
19 VTTaken Down
Screenshot of tinyhub.vip
tinyhub.vip
19 VTTaken Down
Screenshot of tksn33.cyou
tksn33.cyou
19 VTTaken Down
Screenshot of tmall880.cyou
tmall880.cyou
19 VTTaken Down
Screenshot of tmall990.cyou
tmall990.cyou
19 VTTaken Down
Screenshot of tokno.im
tokno.im
19 VTTaken Down
Screenshot of tornadospin.cc
tornadospin.cc
19 VTTaken Down
Screenshot of traders-club24.com
traders-club24.com
19 VTTaken Down
« Prev ... 8 9 10 11 12 13 14 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.