Threat Intelligence Dashboard

March 2026 Report

Detailed threat intelligence for 17,671 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

117,672Total Detected
72,655Taken Down
72%Kill Rate
93.9%VT Coverage
29,957Abuse Reports
Overview Mar 2617,671 Feb 2642,204 Jan 268,931 Dec 2511,773 Nov 2512,579 Oct 258,841 Sep 257,307 Aug 253,788 Jul 25700 Jun 254
March 2026 Intelligence Report 58.1%
17,671
8,382
Taken Down
6,700
Still Live
47.4%
Kill Rate
120h
Avg Response
6.4
Avg VT Score

In March 2026, PhishDestroy detected 6,635 phishing domains, marking a 63.6% decrease from the previous month. Despite this reduction, 3,124 domains remain active, highlighting a takedown rate of only 52.6%. Attackers continue to focus on cryptocurrency platforms, with Coinbase and Exodus being the top targets. The operational impact is significant, as the takedown rate remains below the desired threshold, indicating a need for improved response times from registrars, particularly NICENIC INTERNATIONAL GROUP CO., LIMITED and Cloudflare, Inc..

  • NICENIC INTERNATIONAL GROUP CO., LIMITED is the top abused registrar with 1,334 domains, necessitating immediate escalation.
  • Cryptocurrency platforms, especially Coinbase and Exodus, are under sustained attack, with 86 and 72 domains respectively.
  • The .com TLD remains the most weaponized with 2,369 domains, followed by .dev and .app.
  • The Solana Drainer kit is prevalent, used in 105 instances, posing a significant threat of wallet drains for victims.
  • Peak detection days were March 2nd and March 5th, indicating concentrated phishing campaigns.
  • Mean registrar response time is 47.3 hours, suggesting room for improvement in takedown efficiency.
Outlook
Looking ahead to April 2026, defenders should remain vigilant against cryptocurrency-targeted phishing, particularly involving Solana Drainer kits. Registrars like NICENIC INTERNATIONAL GROUP CO., LIMITED and Cloudflare, Inc. require continued monitoring and pressure to enhance their response times. Expect potential shifts in TLD usage as attackers adapt to increased scrutiny.

Targeted Brands

BrandDomains
Ledger 899
Airdrop Scam 308
Solana 267
Trezor 243
OKX 224
across 219
Coinbase 216
Base 206

March 2026 Domains (17,671)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of www.zaunchpad.com
www.zaunchpad.com
1 VT
Screenshot of www.zenerfastforex.com
www.zenerfastforex.com
1 VTTaken Down
Screenshot of www1.inputecho.co
www1.inputecho.co
1 VTTaken Down
wx6zv.rkelite.pro
1 VTLive
Screenshot of x-ledger-start.pages.dev
x-ledger-start.pages.dev
1 VTLive
Screenshot of x.oilless.lol
x.oilless.lol
1 VT
Screenshot of xaman.build
xaman.build
1 VT
Screenshot of xaportal.com
xaportal.com
1 VTLive
Screenshot of xchange-planet.com
xchange-planet.com
1 VTTaken Down
Screenshot of xeraxium.com
xeraxium.com
1 VTTaken Down
Screenshot of xihlukeit.com
xihlukeit.com
1 VTTaken Down
Screenshot of xmaxe.bet
xmaxe.bet
1 VTTaken Down
Screenshot of xmr-qrcode-generator.com
xmr-qrcode-generator.com
1 VTTaken Down
Screenshot of xn--kakaotalk-th70b.com
xn--kakaotalk-th70b.com
1 VTTaken Down
Screenshot of xn--kjpe-bitcoin-wjb.com
xn--kjpe-bitcoin-wjb.com
1 VTLive
Screenshot of xn--krb2-roa.at
xn--krb2-roa.at
1 VTLive
Screenshot of xn--kspanet-rsc.com
xn--kspanet-rsc.com
1 VTLive
Screenshot of xn--live-pmp-dzb.fun
xn--live-pmp-dzb.fun
1 VTTaken Down
Screenshot of xn--live-pmp-w0b.fun
xn--live-pmp-w0b.fun
1 VTTaken Down
Screenshot of xn--llve-pnp-k5a.fun
xn--llve-pnp-k5a.fun
1 VT
Screenshot of xn--moonsht-bmb.app
xn--moonsht-bmb.app
1 VTLive
Screenshot of xn--pnp-e1a.fun
xn--pnp-e1a.fun
1 VTTaken Down
Screenshot of xn--prnp-vra.fun
xn--prnp-vra.fun
1 VTTaken Down
Screenshot of xn--pump-eza.fun
xn--pump-eza.fun
1 VTLive
Screenshot of xn--wechat-ne0j.com
xn--wechat-ne0j.com
1 VTTaken Down
Screenshot of xornetwork.com
xornetwork.com
1 VTLive
Screenshot of xplhy.com
xplhy.com
1 VTTaken Down
Screenshot of xpliy.com
xpliy.com
1 VTTaken Down
Screenshot of xplly.com
xplly.com
1 VTTaken Down
Screenshot of xpm06.top
xpm06.top
1 VTTaken Down
Screenshot of xpm2.top
xpm2.top
1 VTTaken Down
Screenshot of xrp-node.org
xrp-node.org
1 VTTaken Down
Screenshot of xsolgo.com
xsolgo.com
1 VT
Screenshot of xstox.foundation
xstox.foundation
1 VTLive
Screenshot of xtogetherfit.com
xtogetherfit.com
1 VTTaken Down
Screenshot of xtremefruitexport.com
xtremefruitexport.com
1 VTTaken Down
Screenshot of xurin.pages.dev
xurin.pages.dev
1 VTLive
Screenshot of xwalletweb.io
xwalletweb.io
1 VTLive
Screenshot of xweb3.info
xweb3.info
1 VTLive
Screenshot of xxbum-anime.com
xxbum-anime.com
1 VTLive
Screenshot of xxbum-sextok.com
xxbum-sextok.com
1 VTLive
Screenshot of xxbum-shorts.com
xxbum-shorts.com
1 VTLive
Screenshot of xxbum-twisex.com
xxbum-twisex.com
1 VTLive
Screenshot of xxbum.com
xxbum.com
1 VTLive
Screenshot of yacinetvapp.com.co
yacinetvapp.com.co
1 VTLive
Screenshot of yeahchain-exchange.com
yeahchain-exchange.com
1 VTTaken Down
Screenshot of yellow-waitlist.live
yellow-waitlist.live
1 VT
Screenshot of yieldhub.org
yieldhub.org
1 VTLive
Screenshot of yieldinifinifi.xyz
yieldinifinifi.xyz
1 VT
Screenshot of yieldmultipli.xyz
yieldmultipli.xyz
1 VT
Screenshot of yieldsearcher.xyz
yieldsearcher.xyz
1 VTLive
Screenshot of yjrc.net.cn
yjrc.net.cn
1 VTTaken Down
Screenshot of ymca-xm.org
ymca-xm.org
1 VTTaken Down
Screenshot of yogamonk.online
yogamonk.online
1 VTTaken Down
Screenshot of yohub.one
yohub.one
1 VT
Screenshot of youraislopbores.lat
youraislopbores.lat
1 VT
Screenshot of yourwebaura.com
yourwebaura.com
1 VTLive
Screenshot of yzilabs.vip
yzilabs.vip
1 VTTaken Down
Screenshot of zalandomall.com
zalandomall.com
1 VTTaken Down
Screenshot of zama-og-nft.vercel.app
zama-og-nft.vercel.app
1 VTLive

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.