Threat Intelligence Dashboard

October 2025 Report

Detailed threat intelligence for 8,841 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

149,029Total Detected
101,089Taken Down
71.5%Kill Rate
92.5%VT Coverage
39,748Abuse Reports
Overview May 263,499 Apr 2615,640 Mar 2618,819 Feb 2642,098 Jan 268,930 Dec 2511,773 Nov 2512,579 Oct 258,841 Sep 257,307 Aug 253,788 Jul 25700 Jun 254
October 2025 Intelligence Report 21%
8,841
6,188
Taken Down
2,369
Still Live
70%
Kill Rate
3560h
Avg Response
8.5
Avg VT Score

In October 2025, PhishDestroy detected 8,841 phishing domains, marking a 21.0% increase from the previous month. Notably, NICENIC INTERNATIONAL GROUP CO., LIMITED emerged as the top abuse registrar with 1,206 domains, indicating a potential shift in attacker preferences for domain registration. The targeting of Generic Crypto brands remains prevalent, with 669 domains detected, while Angel Drainer kits were the most used, affecting victims through wallet drains. Despite an 85.7% takedown rate, the mean registrar response time of 2803.0 hours highlights a critical gap in rapid domain deactivation.

  • NICENIC INTERNATIONAL GROUP CO., LIMITED leads registrar abuse with 1,206 domains, necessitating immediate escalation.
  • Crypto-related brands, especially Generic Crypto, are heavily targeted with 669 domains, overshadowing banking and social sectors.
  • The .com TLD remains the most weaponized with 3,256 domains, followed by .xyz and .app.
  • Angel Drainer kits dominate with 1,122 instances, posing significant risks of wallet drain for victims.
  • US-based hosting is overwhelmingly preferred, with 6,383 domains, indicating a need for increased collaboration with US-based providers.
  • The mean registrar response time of 2803.0 hours suggests inefficiencies in detection-to-takedown processes.
Outlook
In November, expect continued targeting of crypto sectors, with potential increases in .xyz and .app TLD abuse. Defenders should prioritize monitoring NICENIC INTERNATIONAL GROUP CO., LIMITED and escalate registrar response times to improve takedown efficiency.

October 2025 Domains (8,841)

Sorted by VirusTotal detections. Click any domain for full security report.

msfidelity.com
13 VTLiveAngel Drainer
mst-monex.baijaanxin.com
13 VTTaken Down
mst-monex.huaweicloud1.cn
13 VTLive
mta.sspl.com.au
13 VTTaken Down
mtytyynh.help
13 VTTaken Down
multiappdash.app
13 VTLiveAngel Drainer
mxmxmxo.wpdevcloud.com
13 VTLive
myetherwalletdesktop.app
13 VTTaken Down
nerdlimited.com
13 VTTaken Down
netcoineslogi-station.webflow.io
13 VTTaken Down
netflix-clone.vly.site
13 VTTaken Down
netflix2024.com
13 VTLive
netflx-account.com
13 VTTaken Down
nextrust.me
13 VTTaken Down
nmovprsk.com
13 VTTaken Down
nodefixer.icu
13 VTTaken DownAngel Drainer
notificationst-001-site1.ktempurl.com
13 VTTaken Down
nutrisheofficialjob.com
13 VTLive
oknrmtcy.gaxlmqrh.raiffeisen-lidhje.com
13 VTLive
omoclaims.xyz
13 VTTaken DownAngel Drainer
open-monex.zhuohonginfo.com
13 VTTaken Down
opensea.finance
13 VTTaken Down
opensea3.com
13 VTTaken Down
org--firef---o--x-addons.webflow.io
13 VTTaken Down
out.sspl.com.au
13 VTTaken Down
p14f.xyz
13 VTTaken Down
p86p.xyz
13 VTTaken Down
p98k.xyz
13 VTTaken Down
pancakeswap.cakepad.cyou
13 VTLive
pancakeswap.finance-app-edge-swap-wallet.cloud
13 VTTaken Down
pancakeswap.finance-cdn-secure-api-alpha.cloud
13 VTTaken Down
panswap.pro
13 VTTaken DownWallet Connect Abuse
parcel190241.wpdevcloud.com
13 VTTaken Down
paxgolds.com
13 VT
pazerx.com
13 VTLive
pc.whatsccu.cc
13 VTTaken Down
pc.whatsdlz.cc
13 VTTaken Down
pc.whatseig.cc
13 VTTaken Down
pc.whatsfvd.cc
13 VTTaken Down
pepemode.com
13 VTLive
pestalnfo.cfd
13 VTLive
phantamullatex.gitbook.io
13 VTTaken Down
phantmmm-wallet.webflow.io
13 VTTaken Down
phantompost.net
13 VTLive
pinetclaimtoken.com
13 VTLive
plasmachainlive.com
13 VTLiveWallet Connect Abuse
plasmadroplive.com
13 VTLive
plume.airdropsalert.live
13 VT
plume.airdrpalerts.sbs
13 VTTaken Down
plumenetwork.airdropsalert.biz
13 VTTaken Down
polkadot.airdropalerts.life
13 VTTaken Down
polymarket.airdropsalerts.sbs
13 VTTaken Down
polymarketprivate.reserved.market
13 VTTaken Down
porlfolio-melamask.app
13 VTTaken DownWallet Connect Abuse
portal--ndax--io-apps.webflow.io
13 VTTaken Down
portal-app-ndax-io-cdn--now.webflow.io
13 VTTaken Down
portal-apps-ndax-io-cdn-s--cdn.webflow.io
13 VTTaken Down
portal-cdn-ndaxx-login.webflow.io
13 VTTaken Down
portal-trezor-io-start.weebly.com
13 VT
portaldepromocionparati.com
13 VTTaken Down
« Prev ... 34 35 36 37 38 39 40 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.