Threat Intelligence Dashboard

July 2025 Report

Detailed threat intelligence for 700 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
July 2025 Intelligence Report 23233.3%
700
663
Taken Down
17
Still Live
94.7%
Kill Rate
6384h
Avg Response
4.3
Avg VT Score

In July 2025, PhishDestroy detected <strong>700</strong> phishing domains, marking a <strong>17400.0%</strong> increase from the previous month, with a takedown rate of <strong>85.1%</strong>. Notably, <strong>Angel Drainer</strong> kits were identified on <strong>183</strong> domains, posing significant risks of wallet drains and seed theft. The mean registrar response time was a concerning <strong>4981.9</strong> hours, highlighting gaps in takedown efficiency. Despite the high volume, our operational impact remains strong with a substantial number of domains taken offline, though registrar responsiveness needs improvement.

  • <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> lead in registrar abuse with <strong>75</strong> and <strong>71</strong> domains respectively, indicating a need for targeted mitigation.
  • Crypto brands remain prime targets with <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> being the most attacked, suggesting a persistent focus on digital asset theft.
  • The <strong>.com</strong> TLD is the most weaponized with <strong>304</strong> domains, followed by <strong>.xyz</strong> with <strong>84</strong>, indicating a preference for these TLDs in phishing campaigns.
  • The dominance of <strong>Angel Drainer</strong> kits across <strong>183</strong> domains suggests a prevalent threat of wallet drains and seed theft.
  • The US hosts the majority of phishing infrastructure with <strong>561</strong> domains, indicating a concentration of malicious activities in this region.
  • The mean detection-to-takedown time remains high at <strong>4981.9</strong> hours, necessitating faster registrar responses to reduce active phishing threats.
Outlook
Given the surge in phishing domains and the focus on crypto brands, defenders should prioritize monitoring for <strong>Angel Drainer</strong> kits and .com TLDs. Registrars like <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> require escalation to enhance response times. Expect continued targeting of crypto sectors, necessitating heightened vigilance and rapid takedown actions.

July 2025 Domains (700)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of cryptonomial.xyz
cryptonomial.xyz
8 VTTaken DownAngel Drainer
Screenshot of curve-en.finance
curve-en.finance
8 VTTaken Down
Screenshot of fintracee.com
fintracee.com
8 VTTaken Down
Screenshot of hypurrfiapp.com
hypurrfiapp.com
8 VTTaken DownAngel Drainer
Screenshot of ixs-sushi.xyz
ixs-sushi.xyz
8 VTTaken Down
Screenshot of neiro-sushi.pro
neiro-sushi.pro
8 VTTaken Down
Screenshot of nelcas.com
nelcas.com
8 VT
Screenshot of oweth.vip
oweth.vip
8 VTTaken DownAngel Drainer
Screenshot of pad-chalngpt.com
pad-chalngpt.com
8 VTTaken Down
Screenshot of phemexglobalfx.com
phemexglobalfx.com
8 VT
Screenshot of 2x-reward.today
2x-reward.today
7 VTTaken Down
Screenshot of 7415decarpiquet.com
7415decarpiquet.com
7 VTTaken DownAngel Drainer
Screenshot of acewalletdrainer.com
acewalletdrainer.com
7 VTTaken Down
Screenshot of affixrevsexplore.run
affixrevsexplore.run
7 VTTaken DownAngel Drainer
Screenshot of blackhols.xyz
blackhols.xyz
7 VTLive
Screenshot of blockdawgclaim.live
blockdawgclaim.live
7 VTTaken DownAngel Drainer
Screenshot of ceolix.com
ceolix.com
7 VTTaken Down
Screenshot of connect-abstractchain.xyz
connect-abstractchain.xyz
7 VTLive
Screenshot of datadapp-manualsdex.xyz
datadapp-manualsdex.xyz
7 VTLiveAngel Drainer
Screenshot of flipcas.com
flipcas.com
7 VTTaken Down
Screenshot of frax-en.xyz
frax-en.xyz
7 VTTaken Down
Screenshot of interpulude.xyz
interpulude.xyz
7 VTTaken DownAngel Drainer
Screenshot of jesusonsui.xyz
jesusonsui.xyz
7 VTTaken DownAngel Drainer
Screenshot of jknioh.com
jknioh.com
7 VTTaken Down
Screenshot of metaweb3app.info
metaweb3app.info
7 VTTaken DownAngel Drainer
Screenshot of nexoramining.org
nexoramining.org
7 VTTaken Down
Screenshot of nodego.asia
nodego.asia
7 VTTaken DownAngel Drainer
Screenshot of os-admin.link
os-admin.link
7 VTTaken Down
Screenshot of oweth.top
oweth.top
7 VTTaken DownAngel Drainer
Screenshot of paal-sushi.xyz
paal-sushi.xyz
7 VTTaken Down
Screenshot of pinetmoney.com
pinetmoney.com
7 VTTaken Down
Screenshot of pump-presale.org
pump-presale.org
7 VTTaken Down
Screenshot of qfsworldgloballedger.org
qfsworldgloballedger.org
7 VTTaken Down
Screenshot of 999claimbye.live
999claimbye.live
6 VTTaken Down
Screenshot of access-auth.xyz
access-auth.xyz
6 VTTaken DownAngel Drainer
Screenshot of authbtcbull.xyz
authbtcbull.xyz
6 VTTaken DownAngel Drainer
Screenshot of block-fi-disbursement-processor.com
block-fi-disbursement-processor.com
6 VTLiveAngel Drainer
Screenshot of blocktrader.biz
blocktrader.biz
6 VTTaken Down
Screenshot of bonsiconize-ven.info
bonsiconize-ven.info
6 VTTaken DownAngel Drainer
Screenshot of capitalcoincylce.com
capitalcoincylce.com
6 VTTaken Down
Screenshot of check-aml.net
check-aml.net
6 VTTaken DownWallet Connect Abuse
Screenshot of coinbase002.xyz
coinbase002.xyz
6 VTTaken Down
Screenshot of coinrion.com
coinrion.com
6 VTTaken Down
Screenshot of coqinu.quest
coqinu.quest
6 VTTaken DownAngel Drainer
Screenshot of cryptotaxup.com
cryptotaxup.com
6 VTTaken DownAngel Drainer
Screenshot of crystalbk.com
crystalbk.com
6 VTTaken Down
Screenshot of dapp-hyperswap.network
dapp-hyperswap.network
6 VTLive
Screenshot of dbybits.com
dbybits.com
6 VTTaken Down
Screenshot of dcsolution.online
dcsolution.online
6 VTTaken DownAngel Drainer
Screenshot of fastnym.com
fastnym.com
6 VTTaken DownAngel Drainer
Screenshot of faucet-zama.com
faucet-zama.com
6 VTTaken DownAngel Drainer
Screenshot of flarenetwork-xrpconnect.com
flarenetwork-xrpconnect.com
6 VTTaken Down
Screenshot of flrportalnet.live
flrportalnet.live
6 VT
Screenshot of fragmetics.xyz
fragmetics.xyz
6 VTTaken DownAngel Drainer
Screenshot of hyperliquid-hub.cc
hyperliquid-hub.cc
6 VTTaken Down
Screenshot of land-app5.top
land-app5.top
6 VTTaken Down
Screenshot of neo-ppeclaim.xyz
neo-ppeclaim.xyz
6 VTTaken Down
Screenshot of p2pexchange-market.com
p2pexchange-market.com
6 VTTaken Down
Screenshot of pancakerswap.com
pancakerswap.com
6 VTTaken DownAngel Drainer
Screenshot of pepeobtain.com
pepeobtain.com
6 VTTaken DownWallet Connect Abuse
« Prev 1 2 3 4 5 6 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.