Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,930 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

149,016Total Detected
100,848Taken Down
71.3%Kill Rate
92.5%VT Coverage
39,740Abuse Reports
Overview May 263,490 Apr 2615,640 Mar 2618,819 Feb 2642,098 Jan 268,930 Dec 2511,773 Nov 2512,579 Oct 258,841 Sep 257,307 Aug 253,788 Jul 25700 Jun 254
January 2026 Intelligence Report 24.1%
8,930
5,595
Taken Down
2,853
Still Live
62.7%
Kill Rate
1532h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a 24.1% decrease in detected phishing domains compared to the previous month, totaling 8,932 domains. Despite this reduction, 1,823 domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at 79.6%, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of 782.6 hours. Notably, there is a shift towards targeting crypto-related brands, with Crypto Scam domains leading at 792 detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • NICENIC INTERNATIONAL GROUP CO., LIMITED remains the top abused registrar with 1,300 domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with Crypto Scam and Coinbase among the top, suggesting attackers are exploiting the volatile crypto market.
  • The .com TLD continues to be the most weaponized, accounting for 3,249 domains, reflecting its broad usage and trust.
  • The solana_drainer kit is the most prevalent, with 213 instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with 2,024 domains, but notable activity is seen in HK and DE, indicating a geographic shift.
  • Registrar response times remain high at 782.6 hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor NICENIC INTERNATIONAL GROUP CO., LIMITED and PDR Ltd. for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,930)

Sorted by VirusTotal detections. Click any domain for full security report.

metamask-wallet-en.framer.ai
14 VTTaken Down
meteora.allitate.live
14 VTLive
metric.doodleslothsnft.xyz
14 VTTaken Down
mexsax.com
14 VTTaken Down
miasbuy-pubgmobile.de5.net
14 VTLive
michaelfalkner1765999723286.1482081.meusitehostgator.com.br
14 VTTaken Down
miovax.com
14 VTTaken Down
monad-mixer.com
14 VTTaken Down
monetrioxil-ia.com
14 VTLive
moodlub.com
14 VTLive
mukomex.com
14 VTTaken Down
munowex.com
14 VTTaken Down
my-site-106944-102670.weeblysite.com
14 VT
nachricht-voice-tonline.kontakt-registration-update.locker
14 VTTaken Down
naturalhavenbening.com
14 VTTaken Down
ndaix-help.webflow.io
14 VTTaken Down
near-bonus.com
14 VTTaken Down
nelowex.com
14 VTLive
netflix-ch-regions-gn6vu.wstd.io
14 VTTaken Down
nexalumeia365-ai.net
14 VTTaken Down
nexovent-84elite.com
14 VTLive
nvkasino.bet
14 VTLive
ny-esspresso.help
14 VTLive
obtain-blaze.net
14 VTTaken DownWallet Connect Abuse
omega-trade.top
14 VTTaken Down
onlinelivegambling.com
14 VTTaken Down
onlyxwin.com
14 VTLive
opensea.com.of-awaiting.com
14 VTTaken Down
openvia.top
14 VTLive
optique-leclercq.be
14 VTTaken Down
orakulcasino.cc
14 VTTaken Down
p112r.xyz
14 VTTaken Down
pelataan.casino
14 VTLive
phantom-wallet.duckdns.org
14 VTTaken Down
phantom-wallett.blogspot.de
14 VTTaken Down
phantombvsw.it.com
14 VTTaken Down
phantomdesktop.app
14 VTTaken Down
phantomwalletextensiondownload.blogspot.com.au
14 VTTaken Down
phantomwalletextensiondownload.blogspot.hk
14 VTTaken Down
pichin399segur.webcindario.com
14 VTTaken Down
pidonex.com
14 VTLive
pidorwex.com
14 VTLive
platzedorionix.com
14 VTLive
playgq.com
14 VTTaken Down
polyfollows.com
14 VTLive
polymarketiq.com
14 VTTaken Down
portal-coinbse-pro-cdn.zapier.app
14 VTTaken Down
portal-flare.online
14 VTLive
prestigiodexlink.net
14 VTTaken Down
primeyield.app
14 VTTaken Down
prowix-edge.net
14 VTLive
pumpfun-celebration.org
14 VTTaken Down
qiye-163-com.rcbeco.com
14 VTTaken Down
quai-nft.io
14 VTLive
quant-events.org
14 VTTaken Down
ranchimallsuiwallet.pages.dev
14 VTLive
rangi.exchange
14 VTLive
recovery-legderlive.run.place
14 VTTaken Down
regal-house.live
14 VTLive
registeredserver.org
14 VTLive
« Prev ... 44 45 46 47 48 49 50 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.