Threat Intelligence Dashboard

July 2025 Report

Detailed threat intelligence for 700 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
July 2025 Intelligence Report 23233.3%
700
663
Taken Down
17
Still Live
94.7%
Kill Rate
6384h
Avg Response
4.3
Avg VT Score

In July 2025, PhishDestroy detected <strong>700</strong> phishing domains, marking a <strong>17400.0%</strong> increase from the previous month, with a takedown rate of <strong>85.1%</strong>. Notably, <strong>Angel Drainer</strong> kits were identified on <strong>183</strong> domains, posing significant risks of wallet drains and seed theft. The mean registrar response time was a concerning <strong>4981.9</strong> hours, highlighting gaps in takedown efficiency. Despite the high volume, our operational impact remains strong with a substantial number of domains taken offline, though registrar responsiveness needs improvement.

  • <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> lead in registrar abuse with <strong>75</strong> and <strong>71</strong> domains respectively, indicating a need for targeted mitigation.
  • Crypto brands remain prime targets with <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> being the most attacked, suggesting a persistent focus on digital asset theft.
  • The <strong>.com</strong> TLD is the most weaponized with <strong>304</strong> domains, followed by <strong>.xyz</strong> with <strong>84</strong>, indicating a preference for these TLDs in phishing campaigns.
  • The dominance of <strong>Angel Drainer</strong> kits across <strong>183</strong> domains suggests a prevalent threat of wallet drains and seed theft.
  • The US hosts the majority of phishing infrastructure with <strong>561</strong> domains, indicating a concentration of malicious activities in this region.
  • The mean detection-to-takedown time remains high at <strong>4981.9</strong> hours, necessitating faster registrar responses to reduce active phishing threats.
Outlook
Given the surge in phishing domains and the focus on crypto brands, defenders should prioritize monitoring for <strong>Angel Drainer</strong> kits and .com TLDs. Registrars like <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> require escalation to enhance response times. Expect continued targeting of crypto sectors, necessitating heightened vigilance and rapid takedown actions.

July 2025 Domains (700)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of p2p-activated.com
p2p-activated.com
11 VTTaken Down
Screenshot of packedtools.tools
packedtools.tools
11 VTTaken Down
Screenshot of perfectminingfx.com
perfectminingfx.com
11 VTTaken Down
Screenshot of qnt-sushi.lat
qnt-sushi.lat
11 VTTaken DownAngel Drainer
Screenshot of ai-quanttrader.org
ai-quanttrader.org
10 VTTaken Down
Screenshot of airdrop-debridge.live
airdrop-debridge.live
10 VTTaken Down
Screenshot of atomic-wallet.pro
atomic-wallet.pro
10 VTTaken Down
Screenshot of avax-sushi.xyz
avax-sushi.xyz
10 VTTaken Down
Screenshot of avmdistritokscod.com
avmdistritokscod.com
10 VTTaken DownAngel Drainer
Screenshot of bitpiemi.com
bitpiemi.com
10 VTTaken Down
Screenshot of bobo-sushi.lat
bobo-sushi.lat
10 VTTaken Down
Screenshot of brad-live.net
brad-live.net
10 VTTaken Down
Screenshot of claims-spheron.network
claims-spheron.network
10 VTTaken DownAngel Drainer
Screenshot of coinassetinvest.com
coinassetinvest.com
10 VT
Screenshot of community-ethereum.com
community-ethereum.com
10 VTTaken DownAngel Drainer
Screenshot of crypto-flipperz.com
crypto-flipperz.com
10 VTTaken Down
Screenshot of cryptowideweb.com
cryptowideweb.com
10 VTTaken DownAngel Drainer
Screenshot of dapptify.com
dapptify.com
10 VTTaken Down
Screenshot of data-manual.xyz
data-manual.xyz
10 VTTaken DownAngel Drainer
Screenshot of fhefaucet.com
fhefaucet.com
10 VTTaken DownAngel Drainer
Screenshot of high-ada.com
high-ada.com
10 VTLive
Screenshot of https-keepkey.com
https-keepkey.com
10 VTTaken Down
Screenshot of hyperliquidbuy.org
hyperliquidbuy.org
10 VTTaken DownAngel Drainer
Screenshot of laf-sushi.cfd
laf-sushi.cfd
10 VTTaken Down
Screenshot of metis-sushi.vip
metis-sushi.vip
10 VTTaken Down
Screenshot of okxedex.com
okxedex.com
10 VTTaken Down
Screenshot of pancakeswap.games
pancakeswap.games
10 VTTaken Down
Screenshot of parti-sushi.xyz
parti-sushi.xyz
10 VTTaken DownAngel Drainer
Screenshot of pepe-sushi.xyz
pepe-sushi.xyz
10 VTTaken DownAngel Drainer
Screenshot of pi-coring.com
pi-coring.com
10 VTTaken Down
Screenshot of aerlifi.net
aerlifi.net
9 VTTaken Down
Screenshot of airdrop.moonveil.click
airdrop.moonveil.click
9 VTTaken DownAngel Drainer
Screenshot of bithpie.com
bithpie.com
9 VTTaken Down
Screenshot of bitpieqc.com
bitpieqc.com
9 VTTaken Down
Screenshot of caminoverdadservices.com
caminoverdadservices.com
9 VTTaken Down
Screenshot of cawa4d.org
cawa4d.org
9 VTTaken Down
Screenshot of coinbtcash.com
coinbtcash.com
9 VTTaken Down
Screenshot of coindbp.vip
coindbp.vip
9 VTTaken Down
Screenshot of crimsonagility.pro
crimsonagility.pro
9 VTTaken Down
Screenshot of cryptoaml-check.com
cryptoaml-check.com
9 VTTaken Down
Screenshot of dashb0ard-littlepepe.com
dashb0ard-littlepepe.com
9 VTTaken DownAngel Drainer
Screenshot of datadapp-manualdex.xyz
datadapp-manualdex.xyz
9 VTTaken DownAngel Drainer
Screenshot of fixedfloatt.com
fixedfloatt.com
9 VTTaken Down
Screenshot of flarehodlclaim.live
flarehodlclaim.live
9 VTTaken Down
Screenshot of fuel-register.quest
fuel-register.quest
9 VTTaken DownAngel Drainer
Screenshot of hedera-rewards.com
hedera-rewards.com
9 VTTaken Down
Screenshot of iconiccityb.com
iconiccityb.com
9 VTTaken Down
Screenshot of neto-launch.com
neto-launch.com
9 VTTaken Down
Screenshot of nl-cionmrt.sbs
nl-cionmrt.sbs
9 VTTaken DownAngel Drainer
Screenshot of noderectificationvip.com
noderectificationvip.com
9 VTTaken Down
Screenshot of pancakswap.org
pancakswap.org
9 VTTaken Down
Screenshot of peerdevelopnetwork.online
peerdevelopnetwork.online
9 VTTaken Down
Screenshot of pi-activating.com
pi-activating.com
9 VTTaken Down
Screenshot of 0xarb.xyz
0xarb.xyz
8 VTTaken Down
Screenshot of aethirclaim.online
aethirclaim.online
8 VTTaken DownAngel Drainer
Screenshot of aixcbstake.xyz
aixcbstake.xyz
8 VTTaken DownAngel Drainer
Screenshot of authenticate-api.xyz
authenticate-api.xyz
8 VTTaken Down
Screenshot of bitmine.top
bitmine.top
8 VTTaken Down
Screenshot of bitpiewa.com
bitpiewa.com
8 VTTaken Down
Screenshot of botto-sushi.xyz
botto-sushi.xyz
8 VTTaken Down
« Prev 1 2 3 4 5 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.