Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of opensea.com.sea-buyer.com
opensea.com.sea-buyer.com
21 VTTaken Down
Screenshot of pengaajuann-danaa-paylaateerr.brodhi.ninja
pengaajuann-danaa-paylaateerr.brodhi.ninja
21 VTTaken Down
Screenshot of phamtom.online
phamtom.online
21 VTTaken Down
Screenshot of project-beta-topaz-83.vercel.app
project-beta-topaz-83.vercel.app
21 VTLive
Screenshot of rbxclaim.net
rbxclaim.net
21 VTTaken Down
Screenshot of robiox.com.ps
robiox.com.ps
21 VTTaken Down
Screenshot of royalcrest-lorin.info
royalcrest-lorin.info
21 VTTaken Down
Screenshot of rugvision.live
rugvision.live
21 VTTaken Down
Screenshot of secure-uphld-oauth.typedream.app
secure-uphld-oauth.typedream.app
21 VT
Screenshot of sexsoldier.duckdns.org
sexsoldier.duckdns.org
21 VTTaken Down
Screenshot of shaw-webmail-1482.netlify.app
shaw-webmail-1482.netlify.app
21 VTLive
Screenshot of shopeevip.online
shopeevip.online
21 VTTaken Down
Screenshot of significant-emoji-236523.framer.app
significant-emoji-236523.framer.app
21 VTTaken Down
Screenshot of soshandorangevocal.godaddysites.com
soshandorangevocal.godaddysites.com
21 VTTaken Down
Screenshot of stella.a2f-livraison.com
stella.a2f-livraison.com
21 VTTaken Down
Screenshot of t-mobile.hpwkg.cc
t-mobile.hpwkg.cc
21 VT
Screenshot of t-mobile.jtdik.cc
t-mobile.jtdik.cc
21 VTTaken Down
Screenshot of t-mobile.lvusy.cc
t-mobile.lvusy.cc
21 VTTaken Down
Screenshot of t-mobile.qbmop.cc
t-mobile.qbmop.cc
21 VTTaken Down
Screenshot of teroom.digital
teroom.digital
21 VTTaken Down
Screenshot of test43593543598.lol
test43593543598.lol
21 VTTaken Down
Screenshot of tksn55.cyou
tksn55.cyou
21 VTTaken Down
Screenshot of tok.alianzati.com
tok.alianzati.com
21 VTTaken Down
Screenshot of trenqor-logic-ai.com
trenqor-logic-ai.com
21 VTTaken Down
Screenshot of trustapp.at
trustapp.at
21 VTTaken Down
Screenshot of trustvirtual.org
trustvirtual.org
21 VTTaken Down
Screenshot of url--uphold-cdn.typedream.app
url--uphold-cdn.typedream.app
21 VT
Screenshot of uuphollddllooqoginnus.godaddysites.com
uuphollddllooqoginnus.godaddysites.com
21 VTTaken Down
Screenshot of verizon.tigvshz.cc
verizon.tigvshz.cc
21 VTTaken Down
Screenshot of verizon.vdwfp.cc
verizon.vdwfp.cc
21 VTTaken Down
Screenshot of w1w.portalrenovacao.com
w1w.portalrenovacao.com
21 VT
Screenshot of wallet-connect-web.app
wallet-connect-web.app
21 VTTaken Down
Screenshot of walletcex.com
walletcex.com
21 VT
Screenshot of web.app-www-whatsapp.com.cn
web.app-www-whatsapp.com.cn
21 VTTaken Down
Screenshot of web.i-whatsapp.com.cn
web.i-whatsapp.com.cn
21 VTTaken Down
Screenshot of web3-secured-ledger.com
web3-secured-ledger.com
21 VTTaken Down
Screenshot of websiteshare.cn
websiteshare.cn
21 VTTaken Down
Screenshot of weekly-nonogon-449910.framer.app
weekly-nonogon-449910.framer.app
21 VTTaken Down
Screenshot of welcome-coinbase-cdns.zapier.app
welcome-coinbase-cdns.zapier.app
21 VTTaken Down
Screenshot of worldlibert-financial.com
worldlibert-financial.com
21 VT
Screenshot of xz.imtokeno.vip
xz.imtokeno.vip
21 VTTaken Down
Screenshot of yth-108845.weeblysite.com
yth-108845.weeblysite.com
21 VTTaken Down
Screenshot of 0471365vip.vip
0471365vip.vip
20 VTTaken Down
Screenshot of 114514.exchange
114514.exchange
20 VTTaken Down
Screenshot of 1165tt.com
1165tt.com
20 VTTaken Down
Screenshot of 1336051.com
1336051.com
20 VTTaken Down
Screenshot of 15654422.com
15654422.com
20 VTTaken Down
Screenshot of 15659966.com
15659966.com
20 VTTaken Down
Screenshot of 1565999777.com
1565999777.com
20 VTTaken Down
Screenshot of 1565vv.com
1565vv.com
20 VTTaken Down
Screenshot of 1565xx.com
1565xx.com
20 VTTaken Down
Screenshot of 1665000666.com
1665000666.com
20 VTTaken Down
Screenshot of 16web.whatsapwcso.com
16web.whatsapwcso.com
20 VTTaken Down
Screenshot of 17755588.com
17755588.com
20 VTTaken Down
Screenshot of 1775ww.com
1775ww.com
20 VTTaken Down
Screenshot of 1958822.com
1958822.com
20 VTTaken Down
Screenshot of 195jjjj.com
195jjjj.com
20 VTTaken Down
Screenshot of 35liq.proxette.cc
35liq.proxette.cc
20 VTTaken Down
Screenshot of 39bt42j.com
39bt42j.com
20 VTTaken Down
Screenshot of 49web.whatsapwacz.com
49web.whatsapwacz.com
20 VTTaken Down
« Prev 1 2 3 4 5 6 7 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.