Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,705Total Detected
144,287Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,537Abuse Reports
Overview Jun 268,177 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of qbcallassistance.com
qbcallassistance.com
20 VTTaken Down
Screenshot of qibabestore.digital
qibabestore.digital
20 VTTaken Down
Screenshot of r.goprox.cc
r.goprox.cc
20 VTTaken Down
Screenshot of regamb.cc
regamb.cc
20 VTTaken Down
Screenshot of reward-boosteth.com
reward-boosteth.com
20 VTTaken Down
Screenshot of sea-2026.com
sea-2026.com
20 VTTaken Down
Screenshot of secured-support-coinbase.com
secured-support-coinbase.com
20 VT
Screenshot of setronweb3ledger.com
setronweb3ledger.com
20 VTTaken Down
Screenshot of siteb.digital
siteb.digital
20 VTTaken Down
Screenshot of softbaok.cc
softbaok.cc
20 VTTaken Down
Screenshot of spotify-clone-api-js.vercel.app
spotify-clone-api-js.vercel.app
20 VTLive
Screenshot of steamcommuinty.cc
steamcommuinty.cc
20 VT
Screenshot of store.steamcommunlty.cc
store.steamcommunlty.cc
20 VTTaken Down
Screenshot of subadikous.digital
subadikous.digital
20 VTTaken Down
Screenshot of suite-trezr-auth-public-faqs.typedream.app
suite-trezr-auth-public-faqs.typedream.app
20 VT
Screenshot of t-mobile.cgdys.cc
t-mobile.cgdys.cc
20 VTTaken Down
Screenshot of t-mobile.cnkde.cc
t-mobile.cnkde.cc
20 VTTaken Down
Screenshot of t-mobile.dkseh.cc
t-mobile.dkseh.cc
20 VTTaken Down
Screenshot of t-mobile.fdes.cc
t-mobile.fdes.cc
20 VTTaken Down
Screenshot of t-mobile.hedsy.cc
t-mobile.hedsy.cc
20 VTTaken Down
Screenshot of t-mobile.igyhd.cc
t-mobile.igyhd.cc
20 VTTaken Down
Screenshot of t-mobile.inorf.cc
t-mobile.inorf.cc
20 VT
Screenshot of t-mobile.kfysx.cc
t-mobile.kfysx.cc
20 VT
Screenshot of t-mobile.kijlo.cc
t-mobile.kijlo.cc
20 VT
Screenshot of t-mobile.qwopt.cc
t-mobile.qwopt.cc
20 VTTaken Down
Screenshot of t-mobile.rmhyc.cc
t-mobile.rmhyc.cc
20 VTTaken Down
Screenshot of t-mobile.sctob.cc
t-mobile.sctob.cc
20 VTTaken Down
Screenshot of t-mobile.sdimj.cc
t-mobile.sdimj.cc
20 VTTaken Down
Screenshot of t-mobile.uejot.cc
t-mobile.uejot.cc
20 VTTaken Down
Screenshot of t-mobile.uxicz.cc
t-mobile.uxicz.cc
20 VTTaken Down
Screenshot of t-mobile.wimpu.cc
t-mobile.wimpu.cc
20 VTTaken Down
Screenshot of t-mobile.xwbqn.cc
t-mobile.xwbqn.cc
20 VTTaken Down
Screenshot of t-mobile.zjrpi.cc
t-mobile.zjrpi.cc
20 VTTaken Down
Screenshot of talksl.digital
talksl.digital
20 VTTaken Down
Screenshot of tapnetic.pro
tapnetic.pro
20 VTTaken Down
Screenshot of tiffany-ntfiff.com
tiffany-ntfiff.com
20 VT
Screenshot of trezoriostat.com
trezoriostat.com
20 VTTaken Down
Screenshot of trezorsuite-docs.vercel.app
trezorsuite-docs.vercel.app
20 VTLive
Screenshot of trustwalletai.club
trustwalletai.club
20 VT
Screenshot of tufinanzalegal.com
tufinanzalegal.com
20 VTTaken Down
Screenshot of uspsvco.com
uspsvco.com
20 VTTaken Down
Screenshot of uw04webzoom.us
uw04webzoom.us
20 VTTaken Down
Screenshot of uyquom.digital
uyquom.digital
20 VTTaken Down
Screenshot of v8plx.vip
v8plx.vip
20 VTTaken Down
Screenshot of vanulynuze.digital
vanulynuze.digital
20 VTTaken Down
Screenshot of verifications-kraken.com
verifications-kraken.com
20 VTTaken Down
Screenshot of verizon.vdwfu.cc
verizon.vdwfu.cc
20 VTTaken Down
Screenshot of verizon.vkesk.cc
verizon.vkesk.cc
20 VTTaken Down
Screenshot of verizon.vkwlx.cc
verizon.vkwlx.cc
20 VTTaken Down
Screenshot of vkftnhaberler.com
vkftnhaberler.com
20 VTTaken Down
Screenshot of web.membersway.com
web.membersway.com
20 VTTaken Down
Screenshot of web3sentinels.com
web3sentinels.com
20 VTTaken Down
Screenshot of webw-whatsapp.com.cn
webw-whatsapp.com.cn
20 VTTaken Down
Screenshot of wis-whatsapp.com.cn
wis-whatsapp.com.cn
20 VTTaken Down
Screenshot of wjm-whatsapp.com.cn
wjm-whatsapp.com.cn
20 VTTaken Down
Screenshot of worthy-slider-508285.framer.app
worthy-slider-508285.framer.app
20 VTTaken Down
Screenshot of wwp-whatsapp.com.cn
wwp-whatsapp.com.cn
20 VTTaken Down
Screenshot of xchallengerz.net
xchallengerz.net
20 VTTaken Down
Screenshot of xcrecacuold.digital
xcrecacuold.digital
20 VTTaken Down
Screenshot of xgamb.cc
xgamb.cc
20 VTTaken Down
« Prev ... 4 5 6 7 8 9 10 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.