Threat Intelligence Dashboard

January 2026 Report

Detailed threat intelligence for 8,924 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,757Total Detected
144,291Taken Down
91.6%Kill Rate
93.4%VT Coverage
45,576Abuse Reports
Overview Jun 268,229 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
January 2026 Intelligence Report 24.2%
8,924
8,270
Taken Down
158
Still Live
92.7%
Kill Rate
1896h
Avg Response
9.6
Avg VT Score

The most significant finding for January 2026 is a <strong>24.1%</strong> decrease in detected phishing domains compared to the previous month, totaling <strong>8,932</strong> domains. Despite this reduction, <strong>1,823</strong> domains remain active, indicating a need for improved takedown strategies. The takedown rate stands at <strong>79.6%</strong>, showing effectiveness but also highlighting a gap in response times, with a mean registrar response time of <strong>782.6</strong> hours. Notably, there is a shift towards targeting crypto-related brands, with <strong>Crypto Scam</strong> domains leading at <strong>792</strong> detections, suggesting a change in attacker focus and potential vulnerabilities in the crypto sector.

  • <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> remains the top abused registrar with <strong>1,300</strong> domains, indicating a persistent issue with registrar oversight.
  • Crypto-related brands are increasingly targeted, with <strong>Crypto Scam</strong> and <strong>Coinbase</strong> among the top, suggesting attackers are exploiting the volatile crypto market.
  • The <strong>.com</strong> TLD continues to be the most weaponized, accounting for <strong>3,249</strong> domains, reflecting its broad usage and trust.
  • The <strong>solana_drainer</strong> kit is the most prevalent, with <strong>213</strong> instances, posing significant risks of wallet drains and seed theft for victims.
  • The US remains the primary hosting geography with <strong>2,024</strong> domains, but notable activity is seen in <strong>HK</strong> and <strong>DE</strong>, indicating a geographic shift.
  • Registrar response times remain high at <strong>782.6</strong> hours, necessitating faster action to reduce active phishing threats.
Outlook
Expect continued focus on crypto-related phishing, with potential increases in domain registrations targeting this sector. Defenders should monitor <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> and <strong>PDR Ltd.</strong> for escalated abuse activity. Watch for new drainer kit variants as attackers refine their methods to exploit cryptocurrency vulnerabilities.

January 2026 Domains (8,924)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of att.hrjoy.cc
att.hrjoy.cc
19 VTTaken Down
Screenshot of att.ixzfh.cc
att.ixzfh.cc
19 VTTaken Down
Screenshot of att.jatkc.cc
att.jatkc.cc
19 VTTaken Down
Screenshot of att.jowek.cc
att.jowek.cc
19 VTTaken Down
Screenshot of att.kackn.cc
att.kackn.cc
19 VTTaken Down
Screenshot of att.kangd.cc
att.kangd.cc
19 VTTaken Down
Screenshot of att.kixnm.cc
att.kixnm.cc
19 VT
Screenshot of att.kxbvn.cc
att.kxbvn.cc
19 VTTaken Down
Screenshot of att.kxrtw.cc
att.kxrtw.cc
19 VTTaken Down
Screenshot of att.lgxon.cc
att.lgxon.cc
19 VTTaken Down
Screenshot of att.lqoue.icu
att.lqoue.icu
19 VTTaken Down
Screenshot of att.skgrl.cc
att.skgrl.cc
19 VTTaken Down
Screenshot of att.vuzat.cc
att.vuzat.cc
19 VT
Screenshot of att.xbmxj.icu
att.xbmxj.icu
19 VTTaken Down
Screenshot of att.xobdp.cc
att.xobdp.cc
19 VTTaken Down
Screenshot of auth-victoryhub.com
auth-victoryhub.com
19 VTTaken Down
Screenshot of b45017.com
b45017.com
19 VTTaken Down
Screenshot of bafkreih3pbvbttbaqeuucxqnsmc6vt32fshfzwsdx7jnlru4idcxedz3si.ipfs.w3s.link
bafkreih3pbvbttbaqeuucxqnsmc6vt32fshfzwsdx7jnlru4idcxedz3si.ipfs.w3s.link
19 VTTaken Down
Screenshot of bet73tt.com
bet73tt.com
19 VTTaken Down
Screenshot of betwintrack.com
betwintrack.com
19 VTTaken Down
Screenshot of bexlorit-ai.net
bexlorit-ai.net
19 VTTaken Down
Screenshot of bhdvalidar.webcindario.com
bhdvalidar.webcindario.com
19 VTTaken Down
Screenshot of biobeautylabofficial.com
biobeautylabofficial.com
19 VTTaken Down
Screenshot of bit.gezmand-tafer.cc
bit.gezmand-tafer.cc
19 VTTaken Down
Screenshot of bitmart-inloggen.com
bitmart-inloggen.com
19 VTTaken Down
Screenshot of blackrose-finbitnex-be.net
blackrose-finbitnex-be.net
19 VTTaken Down
Screenshot of bot-whatsapp.com.cn
bot-whatsapp.com.cn
19 VTTaken Down
Screenshot of breezy-truly-997645.framer.app
breezy-truly-997645.framer.app
19 VTTaken Down
Screenshot of cecrreha.digital
cecrreha.digital
19 VTTaken Down
Screenshot of chainusdcsaving.com
chainusdcsaving.com
19 VTTaken Down
Screenshot of challengereasy.net
challengereasy.net
19 VT
Screenshot of challengerm.pro
challengerm.pro
19 VTTaken Down
Screenshot of claimmyreward.live
claimmyreward.live
19 VTSolana Drainer
Screenshot of coachkaro.com
coachkaro.com
19 VTTaken Down
Screenshot of coinbaim.com
coinbaim.com
19 VTTaken Down
Screenshot of coinvault.live
coinvault.live
19 VTTaken Down
Screenshot of com-receive.live
com-receive.live
19 VTTaken Down
Screenshot of connexion-sfr.info
connexion-sfr.info
19 VTTaken Down
Screenshot of consensy-jplad.com
consensy-jplad.com
19 VT
Screenshot of cpcodmobile.com
cpcodmobile.com
19 VTTaken Down
Screenshot of dailyworkiidpro.com
dailyworkiidpro.com
19 VT
Screenshot of darb.itc.gov.ae-qoex.com
darb.itc.gov.ae-qoex.com
19 VTTaken Down
Screenshot of darb.qmobbilixolk.com
darb.qmobbilixolk.com
19 VTTaken Down
Screenshot of darb.qmobilitcxt.com
darb.qmobilitcxt.com
19 VTTaken Down
Screenshot of desk-109344ma.weeblysite.com
desk-109344ma.weeblysite.com
19 VTTaken Down
Screenshot of dexwin.cc
dexwin.cc
19 VTTaken Down
Screenshot of domainserver1.weebly.com
domainserver1.weebly.com
19 VTTaken Down
Screenshot of e127c.xyz
e127c.xyz
19 VTTaken Down
Screenshot of e67vm91sgf17.trickle.host
e67vm91sgf17.trickle.host
19 VTTaken Down
Screenshot of easy-bank-alpha.vercel.app
easy-bank-alpha.vercel.app
19 VTLive
Screenshot of easy-bank-pi.vercel.app
easy-bank-pi.vercel.app
19 VTLive
Screenshot of easy-bank-psi.vercel.app
easy-bank-psi.vercel.app
19 VTLive
Screenshot of easyswaps.org
easyswaps.org
19 VTTaken Down
Screenshot of eeco.rewardstz.cn
eeco.rewardstz.cn
19 VTTaken Down
Screenshot of eecowj.cn
eecowj.cn
19 VTTaken Down
Screenshot of egamb.cc
egamb.cc
19 VTTaken Down
Screenshot of en-victoryhub.com
en-victoryhub.com
19 VTTaken Down
Screenshot of eng-victory-hub.com
eng-victory-hub.com
19 VTTaken Down
Screenshot of eth-web3.vip
eth-web3.vip
19 VTTaken Down
Screenshot of ethereumlispro.co
ethereumlispro.co
19 VTTaken Down
« Prev ... 6 7 8 9 10 11 12 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.