Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,764Total Detected
144,291Taken Down
91.6%Kill Rate
93.4%VT Coverage
45,581Abuse Reports
Overview Jun 268,236 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of trerzoorr-suite.blogspot.com
trerzoorr-suite.blogspot.com
19 VTTaken Down
Screenshot of truewavewallet-in.online
truewavewallet-in.online
19 VTTaken Down
Screenshot of trust-walet-web.created.app
trust-walet-web.created.app
19 VTTaken Down
Screenshot of trustwalet-cloud.created.app
trustwalet-cloud.created.app
19 VTTaken Down
Screenshot of tudou.831365.cc
tudou.831365.cc
19 VTTaken Down
Screenshot of updatepaal.live
updatepaal.live
19 VT
Screenshot of uu03webzoom.us
uu03webzoom.us
19 VTTaken Down
Screenshot of uup-hoolldlooggiinn.godaddysites.com
uup-hoolldlooggiinn.godaddysites.com
19 VTTaken Down
Screenshot of v3073366-fx5nvmdz6529.volusion.works
v3073366-fx5nvmdz6529.volusion.works
19 VTTaken Down
Screenshot of verificaora.com
verificaora.com
19 VTTaken Down
Screenshot of verify-uniswap.com
verify-uniswap.com
19 VTTaken Down
Screenshot of verizon.bfry.cc
verizon.bfry.cc
19 VTTaken Down
Screenshot of verizon.bjsr.cc
verizon.bjsr.cc
19 VTTaken Down
Screenshot of verizon.fxcast.icu
verizon.fxcast.icu
19 VTTaken Down
Screenshot of verizon.qmobilcfx.cc
verizon.qmobilcfx.cc
19 VTTaken Down
Screenshot of verizon.tfgdaq.cc
verizon.tfgdaq.cc
19 VTTaken Down
Screenshot of verizon.tigvshn.cc
verizon.tigvshn.cc
19 VTTaken Down
Screenshot of verizon.tigvshv.cc
verizon.tigvshv.cc
19 VTTaken Down
Screenshot of verizon.vfdu.cc
verizon.vfdu.cc
19 VTTaken Down
Screenshot of verizon.vkesh.cc
verizon.vkesh.cc
19 VTTaken Down
Screenshot of verizon.vkesr.cc
verizon.vkesr.cc
19 VTTaken Down
Screenshot of verizon.vkesy.cc
verizon.vkesy.cc
19 VTTaken Down
Screenshot of vgamb.cc
vgamb.cc
19 VTTaken Down
Screenshot of virodir.de
virodir.de
19 VTTaken Down
Screenshot of w53i.xyz
w53i.xyz
19 VTTaken Down
Screenshot of web-page-metamask-login.typedream.app
web-page-metamask-login.typedream.app
19 VT
Screenshot of wesoluttion-emendation.com
wesoluttion-emendation.com
19 VTTaken Down
Screenshot of wetransferaudit2026docx.appwrite.network
wetransferaudit2026docx.appwrite.network
19 VTTaken Down
Screenshot of what-can-be-done-if-the-metamask-login-doesnt-work.typedream.app
what-can-be-done-if-the-metamask-login-doesnt-work.typedream.app
19 VT
Screenshot of whatsapp-my.eu.cc
whatsapp-my.eu.cc
19 VTTaken Down
Screenshot of winbroxus.com
winbroxus.com
19 VTTaken Down
Screenshot of windex.cc
windex.cc
19 VTTaken Down
Screenshot of wordelicious.net
wordelicious.net
19 VTTaken Down
Screenshot of wordpress.elzabete3.com
wordpress.elzabete3.com
19 VTTaken Down
Screenshot of ww-usdt.com
ww-usdt.com
19 VTTaken Down
Screenshot of wwb-whatsapp.com.cn
wwb-whatsapp.com.cn
19 VTTaken Down
Screenshot of xaegamb.cc
xaegamb.cc
19 VTTaken Down
Screenshot of xrpceo-25.net
xrpceo-25.net
19 VT
Screenshot of xrpripple.kr
xrpripple.kr
19 VTTaken Down
Screenshot of xsa.sueurioireoae.com
xsa.sueurioireoae.com
19 VTTaken Down
Screenshot of xsa.suueaiireaweeaea.com
xsa.suueaiireaweeaea.com
19 VTTaken Down
Screenshot of y3mint.vip
y3mint.vip
19 VTTaken Down
Screenshot of y8lumo.live
y8lumo.live
19 VTTaken Down
Screenshot of zarabuteemos.shop
zarabuteemos.shop
19 VTTaken Down
Screenshot of zusewin.cc
zusewin.cc
19 VTTaken Down
Screenshot of 15657722.com
15657722.com
18 VTTaken Down
Screenshot of 16155544.com
16155544.com
18 VTTaken Down
Screenshot of 1665ddd.com
1665ddd.com
18 VTTaken Down
Screenshot of 176web.whatsapwacz.com
176web.whatsapwacz.com
18 VTTaken Down
Screenshot of 17752299.com
17752299.com
18 VTTaken Down
Screenshot of 17753377.com
17753377.com
18 VTTaken Down
Screenshot of 192873-coinbase.com
192873-coinbase.com
18 VTTaken Down
Screenshot of 195111111.com
195111111.com
18 VTTaken Down
Screenshot of 195174.com
195174.com
18 VTTaken Down
Screenshot of 19522.com
19522.com
18 VTTaken Down
Screenshot of 195882.com
195882.com
18 VTTaken Down
Screenshot of 2365222444.com
2365222444.com
18 VTTaken Down
Screenshot of 25369.pet
25369.pet
18 VTTaken Down
Screenshot of 25575.com
25575.com
18 VTTaken Down
Screenshot of 6628.org
6628.org
18 VTTaken Down
« Prev ... 9 10 11 12 13 14 15 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.