Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of 25web.whatsapwcso.com
25web.whatsapwcso.com
21 VTTaken Down
Screenshot of 63585.com
63585.com
21 VTTaken Down
Screenshot of 7665aa.com
7665aa.com
21 VTTaken Down
Screenshot of 82777.xyz
82777.xyz
21 VTTaken Down
Screenshot of 88st.vip
88st.vip
21 VTTaken Down
Screenshot of 93web.whatsapwcou.com
93web.whatsapwcou.com
21 VTTaken Down
Screenshot of aldakheelholding.com
aldakheelholding.com
21 VTTaken Down
Screenshot of aliexpressgo.com
aliexpressgo.com
21 VTTaken Down
Screenshot of allegrolokalnie.pl-smart20261.sbs
allegrolokalnie.pl-smart20261.sbs
21 VTTaken Down
Screenshot of amazon-ui-clone-pi.vercel.app
amazon-ui-clone-pi.vercel.app
21 VTLive
Screenshot of amlreport.net
amlreport.net
21 VTTaken Down
Screenshot of anzsupportchat.com
anzsupportchat.com
21 VTTaken Down
Screenshot of att.drutb.cc
att.drutb.cc
21 VTTaken Down
Screenshot of bet365sport19.com
bet365sport19.com
21 VT
Screenshot of bingejobs.com
bingejobs.com
21 VTTaken Down
Screenshot of bitz.rolastopas.cc
bitz.rolastopas.cc
21 VTTaken Down
Screenshot of bonitetaktls.digital
bonitetaktls.digital
21 VTTaken Down
Screenshot of bybit-auditor.one
bybit-auditor.one
21 VTTaken Down
Screenshot of captioto.com
captioto.com
21 VTTaken Down
Screenshot of casetun.com
casetun.com
21 VTTaken Down
Screenshot of challengem.net
challengem.net
21 VTLive
Screenshot of cltext.digital
cltext.digital
21 VT
Screenshot of cmonline-klantportaal.com
cmonline-klantportaal.com
21 VT
Screenshot of coinbase-io.meku.app
coinbase-io.meku.app
21 VTTaken Down
Screenshot of concet-trezor-auth-us.typedream.app
concet-trezor-auth-us.typedream.app
21 VT
Screenshot of d4nz1k.nftlm.biz.id
d4nz1k.nftlm.biz.id
21 VTTaken Down
Screenshot of darb.ae-qone.com
darb.ae-qone.com
21 VTTaken Down
Screenshot of darb.itc.gov.ae-docs.com
darb.itc.gov.ae-docs.com
21 VTTaken Down
Screenshot of darb.itc.gov.ae-qoez.com
darb.itc.gov.ae-qoez.com
21 VTTaken Down
Screenshot of darb.itc.gov.ae-qovt.com
darb.itc.gov.ae-qovt.com
21 VTTaken Down
darb.qmobilitbyd.com
21 VTTaken Down
darb.qmobilitthyd.com
21 VTTaken Down
Screenshot of darb.qmobilitysis.com
darb.qmobilitysis.com
21 VTTaken Down
Screenshot of dd5cea65-8789-4278-9de6-38e02b38d22d-00-8on25l5vyms5.riker.replit.dev
dd5cea65-8789-4278-9de6-38e02b38d22d-00-8on25l5vyms5.riker.replit.dev
21 VTTaken Down
Screenshot of docs-uphold-wallet.blogspot.pt
docs-uphold-wallet.blogspot.pt
21 VTTaken Down
Screenshot of dojoker.duckdns.org
dojoker.duckdns.org
21 VTTaken Down
Screenshot of easy-bank-landing-page-olive.vercel.app
easy-bank-landing-page-olive.vercel.app
21 VTLive
Screenshot of erajmore.digital
erajmore.digital
21 VTTaken Down
Screenshot of ethereum-cormax-platform.co
ethereum-cormax-platform.co
21 VTTaken Down
Screenshot of ethereum-cormax.co
ethereum-cormax.co
21 VTTaken Down
Screenshot of ethereumcormax.co
ethereumcormax.co
21 VTTaken Down
Screenshot of ethereumoluxapp.net
ethereumoluxapp.net
21 VTTaken Down
Screenshot of gbalance.dtemiemie.online
gbalance.dtemiemie.online
21 VTTaken Down
Screenshot of geldchantix-trade.com
geldchantix-trade.com
21 VTTaken Down
Screenshot of gopay13.eqxd.top
gopay13.eqxd.top
21 VTTaken Down
Screenshot of gopay21.eqxd.top
gopay21.eqxd.top
21 VTTaken Down
Screenshot of gopay4.kyiu.top
gopay4.kyiu.top
21 VTTaken Down
Screenshot of hubchallengerz.pro
hubchallengerz.pro
21 VTTaken Down
Screenshot of hubcok.digital
hubcok.digital
21 VTTaken Down
Screenshot of igichdejib.digital
igichdejib.digital
21 VTTaken Down
Screenshot of lbplaccesss.com
lbplaccesss.com
21 VTTaken Down
Screenshot of lift-9-whatsapp.herokuapp.com
lift-9-whatsapp.herokuapp.com
21 VTLive
Screenshot of mail.cipamazonas.org.pe
mail.cipamazonas.org.pe
21 VTTaken Down
Screenshot of mysteryclaims6345-live.vercel.app
mysteryclaims6345-live.vercel.app
21 VTTaken DownAngel Drainer
Screenshot of mysteryclaims6346-live.vercel.app
mysteryclaims6346-live.vercel.app
21 VTTaken DownAngel Drainer
Screenshot of mysteryclaims6349-live.vercel.app
mysteryclaims6349-live.vercel.app
21 VTTaken DownAngel Drainer
Screenshot of netflixclone-git-main-alstonchan.vercel.app
netflixclone-git-main-alstonchan.vercel.app
21 VTLive
Screenshot of nn1505.com
nn1505.com
21 VTTaken Down
Screenshot of ogrrod.digital
ogrrod.digital
21 VTTaken Down
Screenshot of omquisofy.digital
omquisofy.digital
21 VTTaken Down
« Prev 1 2 3 4 5 6 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.