Threat Intelligence Dashboard

July 2025 Report

Detailed threat intelligence for 700 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
July 2025 Intelligence Report 23233.3%
700
663
Taken Down
17
Still Live
94.7%
Kill Rate
6384h
Avg Response
4.3
Avg VT Score

In July 2025, PhishDestroy detected <strong>700</strong> phishing domains, marking a <strong>17400.0%</strong> increase from the previous month, with a takedown rate of <strong>85.1%</strong>. Notably, <strong>Angel Drainer</strong> kits were identified on <strong>183</strong> domains, posing significant risks of wallet drains and seed theft. The mean registrar response time was a concerning <strong>4981.9</strong> hours, highlighting gaps in takedown efficiency. Despite the high volume, our operational impact remains strong with a substantial number of domains taken offline, though registrar responsiveness needs improvement.

  • <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> lead in registrar abuse with <strong>75</strong> and <strong>71</strong> domains respectively, indicating a need for targeted mitigation.
  • Crypto brands remain prime targets with <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> being the most attacked, suggesting a persistent focus on digital asset theft.
  • The <strong>.com</strong> TLD is the most weaponized with <strong>304</strong> domains, followed by <strong>.xyz</strong> with <strong>84</strong>, indicating a preference for these TLDs in phishing campaigns.
  • The dominance of <strong>Angel Drainer</strong> kits across <strong>183</strong> domains suggests a prevalent threat of wallet drains and seed theft.
  • The US hosts the majority of phishing infrastructure with <strong>561</strong> domains, indicating a concentration of malicious activities in this region.
  • The mean detection-to-takedown time remains high at <strong>4981.9</strong> hours, necessitating faster registrar responses to reduce active phishing threats.
Outlook
Given the surge in phishing domains and the focus on crypto brands, defenders should prioritize monitoring for <strong>Angel Drainer</strong> kits and .com TLDs. Registrars like <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> require escalation to enhance response times. Expect continued targeting of crypto sectors, necessitating heightened vigilance and rapid takedown actions.

July 2025 Domains (700)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of pi-xchange.com
pi-xchange.com
6 VTTaken Down
Screenshot of pumpswaps.fun
pumpswaps.fun
6 VTTaken Down
Screenshot of qfsglobalz.com
qfsglobalz.com
6 VTTaken Down
Screenshot of 30303033.xyz
30303033.xyz
5 VTTaken Down
Screenshot of 5eplay-accept.xyz
5eplay-accept.xyz
5 VTTaken Down
Screenshot of aevo-sushi.cfd
aevo-sushi.cfd
5 VTTaken DownAngel Drainer
Screenshot of airdrop-delabs.xyz
airdrop-delabs.xyz
5 VTTaken Down
Screenshot of aletheacapro.com
aletheacapro.com
5 VTTaken Down
Screenshot of bitminepool.xyz
bitminepool.xyz
5 VTTaken DownAngel Drainer
Screenshot of blockdagwork.net
blockdagwork.net
5 VTTaken DownWallet Connect Abuse
Screenshot of bnb100k-register.network
bnb100k-register.network
5 VTTaken Down
Screenshot of bookmaker-drop.xyz
bookmaker-drop.xyz
5 VTTaken DownAngel Drainer
Screenshot of btcpepe.lol
btcpepe.lol
5 VTTaken DownAngel Drainer
Screenshot of bybitcard.com
bybitcard.com
5 VT
Screenshot of bybitgum.org
bybitgum.org
5 VTTaken Down
Screenshot of claims-caldera.foundation
claims-caldera.foundation
5 VTTaken DownAngel Drainer
Screenshot of cobydex.com
cobydex.com
5 VTTaken Down
Screenshot of collab-shard-land.com
collab-shard-land.com
5 VTTaken Down
Screenshot of collabs-auth.xyz
collabs-auth.xyz
5 VTTaken Down
Screenshot of coresky.cyou
coresky.cyou
5 VTTaken DownAngel Drainer
Screenshot of corkclaim.cloud
corkclaim.cloud
5 VTTaken Down
Screenshot of crypweb3networks.org
crypweb3networks.org
5 VTTaken Down
Screenshot of dapp-resolver.xyz
dapp-resolver.xyz
5 VTTaken DownAngel Drainer
Screenshot of deepbook-ai.com
deepbook-ai.com
5 VTTaken Down
Screenshot of fuelconnects.net
fuelconnects.net
5 VTTaken DownAngel Drainer
Screenshot of grt-sushi.cfd
grt-sushi.cfd
5 VTTaken DownAngel Drainer
Screenshot of https-bybit.com
https-bybit.com
5 VTTaken Down
Screenshot of htxexchange.live
htxexchange.live
5 VTTaken Down
Screenshot of imf-registers.quest
imf-registers.quest
5 VTTaken Down
Screenshot of naarisprotocol.com
naarisprotocol.com
5 VTTaken DownAngel Drainer
Screenshot of official-mar.com
official-mar.com
5 VT
Screenshot of opensea-welcome.xyz
opensea-welcome.xyz
5 VTTaken Down
Screenshot of p2pmainnet.com
p2pmainnet.com
5 VTTaken Down
Screenshot of pay-seller.com
pay-seller.com
5 VTTaken Down
Screenshot of peudlle.finance
peudlle.finance
5 VTTaken DownAngel Drainer
Screenshot of phantomfinanceinvestment.world
phantomfinanceinvestment.world
5 VTTaken Down
Screenshot of pibased.com
pibased.com
5 VTTaken Down
Screenshot of pumpclaim.xyz
pumpclaim.xyz
5 VTTaken Down
Screenshot of pumppfunsol.net
pumppfunsol.net
5 VTTaken Down
Screenshot of qfsledgers.com
qfsledgers.com
5 VTTaken Down
Screenshot of qubetlcsreward.xyz
qubetlcsreward.xyz
5 VTTaken DownAngel Drainer
Screenshot of 30eth.com
30eth.com
4 VTTaken DownAngel Drainer
Screenshot of aavegotchimigrate.com
aavegotchimigrate.com
4 VTTaken Down
Screenshot of ai-eva.xyz
ai-eva.xyz
4 VTTaken DownAngel Drainer
Screenshot of airdropsonics.live
airdropsonics.live
4 VTTaken Down
Screenshot of asterdexi.com
asterdexi.com
4 VTTaken Down
Screenshot of bitget-walletsecurity.com
bitget-walletsecurity.com
4 VTTaken DownAngel Drainer
Screenshot of byreal-register.network
byreal-register.network
4 VTTaken DownAngel Drainer
Screenshot of byreal.world
byreal.world
4 VTTaken DownAngel Drainer
Screenshot of catecoinpool.xyz
catecoinpool.xyz
4 VTTaken Down
Screenshot of cbybit.com
cbybit.com
4 VTTaken Down
Screenshot of claims-eclipse.xyz
claims-eclipse.xyz
4 VTTaken DownAngel Drainer
Screenshot of coinanex.com
coinanex.com
4 VTTaken Down
Screenshot of coinercos.com
coinercos.com
4 VTTaken Down
Screenshot of coinizex.com
coinizex.com
4 VTTaken Down
Screenshot of collect-xrp.com
collect-xrp.com
4 VTTaken Down
Screenshot of cryptend.com
cryptend.com
4 VTTaken Down
Screenshot of dappserver.icu
dappserver.icu
4 VTTaken DownAngel Drainer
Screenshot of fdn-plasma.to
fdn-plasma.to
4 VTTaken DownAngel Drainer
Screenshot of fintrustinvestment.com
fintrustinvestment.com
4 VTTaken Down
« Prev 1 2 3 4 5 6 7 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.