Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of 1665pp.com
1665pp.com
22 VTTaken Down
Screenshot of 195444666.com
195444666.com
22 VTTaken Down
Screenshot of 2985web.whatsapwcox.com
2985web.whatsapwcox.com
22 VTTaken Down
Screenshot of 6hcp99.com
6hcp99.com
22 VTTaken Down
Screenshot of 6web.whatsapwcso.com
6web.whatsapwcso.com
22 VTTaken Down
Screenshot of att.qjwar.cc
att.qjwar.cc
22 VT
Screenshot of balaxipharma.gt
balaxipharma.gt
22 VTTaken Down
Screenshot of caissedallocationsfamiliales.com
caissedallocationsfamiliales.com
22 VTTaken Down
Screenshot of chma.digital
chma.digital
22 VT
Screenshot of claim-pengu.live
claim-pengu.live
22 VTTaken Down
Screenshot of coaakkzz.top
coaakkzz.top
22 VTTaken Down
Screenshot of ctkkponbri.com
ctkkponbri.com
22 VTTaken Down
Screenshot of darb.ae-qocs.com
darb.ae-qocs.com
22 VTTaken Down
Screenshot of darb.qmobilitucj.com
darb.qmobilitucj.com
22 VTTaken Down
Screenshot of darbqmobilityae.com
darbqmobilityae.com
22 VTTaken Down
Screenshot of easy-bank-theta.vercel.app
easy-bank-theta.vercel.app
22 VTLive
Screenshot of easybank-landing-page-rabwinter.vercel.app
easybank-landing-page-rabwinter.vercel.app
22 VTLive
Screenshot of emsysten.top
emsysten.top
22 VTTaken Down
Screenshot of ethereumhubdefi.net
ethereumhubdefi.net
22 VTTaken Down
Screenshot of ethereumlispro.net
ethereumlispro.net
22 VTTaken Down
Screenshot of exciting-white-3qjtseqzpp.edgeone.dev
exciting-white-3qjtseqzpp.edgeone.dev
22 VTTaken Down
Screenshot of hungfapeper.sbs
hungfapeper.sbs
22 VTTaken Down
Screenshot of instaentertainers.com
instaentertainers.com
22 VTTaken Down
Screenshot of klantportaal38201184.com
klantportaal38201184.com
22 VTTaken Down
Screenshot of ledger-live-wallet-web-start-us.typedream.app
ledger-live-wallet-web-start-us.typedream.app
22 VTTaken Down
Screenshot of livemint-mysteryboxs050.vercel.app
livemint-mysteryboxs050.vercel.app
22 VTTaken Down
Screenshot of llg-whatsapp.com.cn
llg-whatsapp.com.cn
22 VTTaken Down
Screenshot of login.login.userverifylogin.com
login.login.userverifylogin.com
22 VTTaken Down
Screenshot of login.userverifylogin.com
login.userverifylogin.com
22 VTTaken Down
Screenshot of m.515711111.com
m.515711111.com
22 VTTaken Down
Screenshot of mx-tiktok-shop-vip.com
mx-tiktok-shop-vip.com
22 VTTaken Down
Screenshot of needet.digital
needet.digital
22 VTTaken Down
Screenshot of net1f1ix.com
net1f1ix.com
22 VTTaken Down
Screenshot of netflix-clone-navy-beta.vercel.app
netflix-clone-navy-beta.vercel.app
22 VTLive
Screenshot of owhwentown.digital
owhwentown.digital
22 VT
Screenshot of proqema.digital
proqema.digital
22 VT
Screenshot of skilltestpro.id
skilltestpro.id
22 VTTaken Down
Screenshot of tiktoklog.vercel.app
tiktoklog.vercel.app
22 VTLive
Screenshot of tufinanzadeapoyo.com
tufinanzadeapoyo.com
22 VTTaken Down
Screenshot of uqholdxxogin-us.godaddysites.com
uqholdxxogin-us.godaddysites.com
22 VTTaken Down
Screenshot of web.denglu-whatsapp.com.cn
web.denglu-whatsapp.com.cn
22 VTTaken Down
Screenshot of web3ledgersecured.com
web3ledgersecured.com
22 VTTaken Down
Screenshot of wwt-whatsapp.com.cn
wwt-whatsapp.com.cn
22 VTTaken Down
Screenshot of 03c5157.com
03c5157.com
21 VTTaken Down
Screenshot of 1111365zw.cc
1111365zw.cc
21 VTTaken Down
Screenshot of 139web.whatsapwacz.com
139web.whatsapwacz.com
21 VTTaken Down
Screenshot of 1565nnnnn.com
1565nnnnn.com
21 VTTaken Down
Screenshot of 1615jjjj.com
1615jjjj.com
21 VTTaken Down
Screenshot of 16659988.com
16659988.com
21 VTTaken Down
Screenshot of 1665app.com
1665app.com
21 VTTaken Down
Screenshot of 1665rrr.com
1665rrr.com
21 VTTaken Down
Screenshot of 17753322.com
17753322.com
21 VTTaken Down
Screenshot of 1775tt.com
1775tt.com
21 VTTaken Down
Screenshot of 195111222.com
195111222.com
21 VTTaken Down
Screenshot of 195233.com
195233.com
21 VTTaken Down
Screenshot of 195269.com
195269.com
21 VTTaken Down
Screenshot of 195333222.com
195333222.com
21 VTTaken Down
Screenshot of 195927.com
195927.com
21 VTTaken Down
Screenshot of 195gggg.com
195gggg.com
21 VTTaken Down
Screenshot of 225web.whatsapwacz.com
225web.whatsapwacz.com
21 VTTaken Down
« Prev 1 2 3 4 5 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.