Threat Intelligence Dashboard

November 2025 Report

Detailed threat intelligence for 12,578 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
November 2025 Intelligence Report 42.3%
12,578
11,873
Taken Down
269
Still Live
94.4%
Kill Rate
3198h
Avg Response
9.3
Avg VT Score

In November 2025, PhishDestroy detected <strong>12,580</strong> phishing domains, marking a <strong>42.3%</strong> increase from the previous month. The takedown rate was <strong>85.4%</strong>, with <strong>1,842</strong> domains still active. Notably, <strong>Crypto Scam</strong> targeting surged with <strong>990</strong> domains, reflecting a shift towards cryptocurrency-related phishing. The mean registrar response time remains a concern at <strong>2189.3</strong> hours, indicating potential delays in domain takedowns.

  • <strong>DYNADOT LLC</strong> leads registrar abuse with <strong>1,583</strong> domains, followed by <strong>Cloudflare, Inc.</strong> and <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong>.
  • Crypto-related brands like <strong>Coinbase</strong> (<strong>422</strong>) and <strong>Kraken</strong> (<strong>350</strong>) are primary targets, overshadowing traditional sectors.
  • The <strong>.com</strong> TLD remains the most weaponized with <strong>3,945</strong> domains, while <strong>.io</strong> and <strong>.xyz</strong> also see significant usage.
  • <strong>Angel Drainer</strong> is the most prevalent kit with <strong>842</strong> instances, posing risks of wallet draining and seed theft.
  • The US hosts the majority of phishing infrastructure with <strong>9,485</strong> domains, but Germany and Sweden are emerging hotspots.
  • Registrar response inefficiency persists, with a mean time of <strong>2189.3</strong> hours, necessitating faster action.
Outlook
Expect continued growth in crypto-targeted phishing, particularly against platforms like <strong>Coinbase</strong> and <strong>Kraken</strong>. Registrars such as <strong>DYNADOT LLC</strong> and <strong>Cloudflare, Inc.</strong> require heightened scrutiny and faster response times. Watch for increased adoption of drainer kits like <strong>Angel Drainer</strong>, which could exacerbate financial losses for victims.

November 2025 Domains (12,578)

Sorted by VirusTotal detections. Click any domain for full security report.

phanowallet.org
20 VT
Screenshot of platform-terms-and-accountability.pages.dev
platform-terms-and-accountability.pages.dev
20 VTTaken Down
Screenshot of produbancocreditos.netlify.app
produbancocreditos.netlify.app
20 VTTaken Down
Screenshot of reserved-customers-742084.framer.app
reserved-customers-742084.framer.app
20 VTTaken Down
Screenshot of roboux2025.netlify.app
roboux2025.netlify.app
20 VTLive
sbbin.vercel.app
20 VTTaken Down
Screenshot of secure-sqare-authh.typedream.app
secure-sqare-authh.typedream.app
20 VTTaken Down
Screenshot of sgin9-alibaba.mdbgo.io
sgin9-alibaba.mdbgo.io
20 VTTaken Down
Screenshot of shop.tkjsonlin.cc
shop.tkjsonlin.cc
20 VTTaken Down
Screenshot of stunning-octo-fiesta.vercel.app
stunning-octo-fiesta.vercel.app
20 VTTaken Down
Screenshot of suncoust.click
suncoust.click
20 VTTaken Down
Screenshot of upohold-logiinus.godaddysites.com
upohold-logiinus.godaddysites.com
20 VTTaken Down
Screenshot of usersignup.agency-partner-register.com
usersignup.agency-partner-register.com
20 VTTaken Down
Screenshot of verificacao.7gamesbr.link
verificacao.7gamesbr.link
20 VTTaken Down
Screenshot of vozanosports.com
vozanosports.com
20 VTTaken Down
Screenshot of web-sso-coinbase-app.square.site
web-sso-coinbase-app.square.site
20 VTTaken Down
Screenshot of whatsappget.com
whatsappget.com
20 VTTaken Down
Screenshot of www3-vpass.cjmvx.cn
www3-vpass.cjmvx.cn
20 VTTaken Down
Screenshot of www3-vpass.godqo.cn
www3-vpass.godqo.cn
20 VTTaken Down
Screenshot of www3-vpass.nbeec.cn
www3-vpass.nbeec.cn
20 VTTaken Down
Screenshot of ymsox.com
ymsox.com
20 VTTaken Down
Screenshot of zh-whatsappweb-co.com.cn
zh-whatsappweb-co.com.cn
20 VTTaken Down
Screenshot of ziply.pk
ziply.pk
20 VT
Screenshot of zs7421.com
zs7421.com
20 VT
Screenshot of 163-5-109-112.cprapid.com
163-5-109-112.cprapid.com
19 VTTaken Down
Screenshot of 212311.netlify.app
212311.netlify.app
19 VTTaken Down
Screenshot of 365hty1.vip
365hty1.vip
19 VTTaken Down
Screenshot of 38nxtbzi.union-label.com
38nxtbzi.union-label.com
19 VTTaken Down
Screenshot of 5smdr2nw.at-the-lake.com
5smdr2nw.at-the-lake.com
19 VTTaken Down
Screenshot of 692799de4101b667ac2c.appwrite.network
692799de4101b667ac2c.appwrite.network
19 VTTaken Down
Screenshot of 806xpj.com
806xpj.com
19 VTTaken Down
Screenshot of 85-215-175-92.cprapid.com
85-215-175-92.cprapid.com
19 VTTaken Down
Screenshot of acc-integrity-check-centre.pages.dev
acc-integrity-check-centre.pages.dev
19 VTTaken Down
Screenshot of accountcenter-docuplexa-dsa1509xz.netlify.app
accountcenter-docuplexa-dsa1509xz.netlify.app
19 VTLive
Screenshot of accshomecnfrm0log.github.io
accshomecnfrm0log.github.io
19 VTLive
Screenshot of aigle-insightstreamsoft.com
aigle-insightstreamsoft.com
19 VTTaken Down
Screenshot of ak.core-service.my.id
ak.core-service.my.id
19 VTTaken Down
Screenshot of akunkerjaonline.com
akunkerjaonline.com
19 VTTaken Down
Screenshot of amazon-io.vercel.app
amazon-io.vercel.app
19 VTLive
Screenshot of amber-trace.pages.dev
amber-trace.pages.dev
19 VTTaken Down
Screenshot of animocabrands.page
animocabrands.page
19 VTTaken DownWallet Connect Abuse
Screenshot of annuler-connexion.com
annuler-connexion.com
19 VTTaken Down
Screenshot of app-cowsw-c1.top
app-cowsw-c1.top
19 VTTaken DownAngel Drainer
Screenshot of app.trezoriosstart.com
app.trezoriosstart.com
19 VTTaken Down
Screenshot of aqif567gg.github.io
aqif567gg.github.io
19 VTLive
Screenshot of assistance-amelienligne.com
assistance-amelienligne.com
19 VTTaken Down
Screenshot of auth--bitbuy-cda--cdn-azure.dora.run
auth--bitbuy-cda--cdn-azure.dora.run
19 VTTaken Down
Screenshot of b45061.com
b45061.com
19 VTTaken Down
Screenshot of bafkreie4pdizjo3n36fx25nbqcvazgntc3ib5zxygqe6ewmxz2tw5wognm.ipfs.dweb.link
bafkreie4pdizjo3n36fx25nbqcvazgntc3ib5zxygqe6ewmxz2tw5wognm.ipfs.dweb.link
19 VTTaken Down
Screenshot of bafybeibi3azpv4l5jnrkaudilpvkqxjtdhpateq642uaous4mckedowr3u.ipfs.dweb.link
bafybeibi3azpv4l5jnrkaudilpvkqxjtdhpateq642uaous4mckedowr3u.ipfs.dweb.link
19 VTTaken Down
Screenshot of bafybeiguc2wldadcecll4xc5ikl6xkbl2vb5tu4pq2vmr6prjcls4oogiy.ipfs.dweb.link
bafybeiguc2wldadcecll4xc5ikl6xkbl2vb5tu4pq2vmr6prjcls4oogiy.ipfs.dweb.link
19 VTTaken Down
Screenshot of bellsouth-att-signing-b613f6.webflow.io
bellsouth-att-signing-b613f6.webflow.io
19 VTTaken Down
Screenshot of branch-main-9dfef01.appwrite.network
branch-main-9dfef01.appwrite.network
19 VTLive
Screenshot of breathtaking-intend-971835.framer.app
breathtaking-intend-971835.framer.app
19 VTTaken Down
Screenshot of business-for-advertisers-takedown-help.pages.dev
business-for-advertisers-takedown-help.pages.dev
19 VTTaken Down
Screenshot of cagateckinsaat.com
cagateckinsaat.com
19 VTTaken Down
Screenshot of case26355.agency-partner-apply.com
case26355.agency-partner-apply.com
19 VTTaken Down
Screenshot of cef.atualizacaocadastral.co.ua
cef.atualizacaocadastral.co.ua
19 VTTaken Down
Screenshot of changenovv.net
changenovv.net
19 VTTaken Down
Screenshot of ckoinbaseprologinus.godaddysites.com
ckoinbaseprologinus.godaddysites.com
19 VTTaken Down
« Prev 1 2 3 4 5 6 7 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.