Threat Intelligence Dashboard

July 2025 Report

Detailed threat intelligence for 700 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,686Total Detected
144,287Taken Down
91.7%Kill Rate
93.4%VT Coverage
45,517Abuse Reports
Overview Jun 268,158 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
July 2025 Intelligence Report 23233.3%
700
663
Taken Down
17
Still Live
94.7%
Kill Rate
6384h
Avg Response
4.3
Avg VT Score

In July 2025, PhishDestroy detected <strong>700</strong> phishing domains, marking a <strong>17400.0%</strong> increase from the previous month, with a takedown rate of <strong>85.1%</strong>. Notably, <strong>Angel Drainer</strong> kits were identified on <strong>183</strong> domains, posing significant risks of wallet drains and seed theft. The mean registrar response time was a concerning <strong>4981.9</strong> hours, highlighting gaps in takedown efficiency. Despite the high volume, our operational impact remains strong with a substantial number of domains taken offline, though registrar responsiveness needs improvement.

  • <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> lead in registrar abuse with <strong>75</strong> and <strong>71</strong> domains respectively, indicating a need for targeted mitigation.
  • Crypto brands remain prime targets with <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> being the most attacked, suggesting a persistent focus on digital asset theft.
  • The <strong>.com</strong> TLD is the most weaponized with <strong>304</strong> domains, followed by <strong>.xyz</strong> with <strong>84</strong>, indicating a preference for these TLDs in phishing campaigns.
  • The dominance of <strong>Angel Drainer</strong> kits across <strong>183</strong> domains suggests a prevalent threat of wallet drains and seed theft.
  • The US hosts the majority of phishing infrastructure with <strong>561</strong> domains, indicating a concentration of malicious activities in this region.
  • The mean detection-to-takedown time remains high at <strong>4981.9</strong> hours, necessitating faster registrar responses to reduce active phishing threats.
Outlook
Given the surge in phishing domains and the focus on crypto brands, defenders should prioritize monitoring for <strong>Angel Drainer</strong> kits and .com TLDs. Registrars like <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> require escalation to enhance response times. Expect continued targeting of crypto sectors, necessitating heightened vigilance and rapid takedown actions.

July 2025 Domains (700)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of aiauthenticate.xyz
aiauthenticate.xyz
2 VTTaken DownAngel Drainer
Screenshot of aidefiableauto.com
aidefiableauto.com
2 VTTaken Down
Screenshot of airdrop-stoopidcat.fun
airdrop-stoopidcat.fun
2 VTTaken DownAngel Drainer
Screenshot of airdrop-x.xyz
airdrop-x.xyz
2 VTTaken Down
Screenshot of airswapreward.live
airswapreward.live
2 VTTaken Down
Screenshot of aixvc-register.info
aixvc-register.info
2 VTTaken DownAngel Drainer
Screenshot of asssister.xyz
asssister.xyz
2 VTTaken Down
Screenshot of atlanticargoexpress.com
atlanticargoexpress.com
2 VTTaken Down
Screenshot of avm-register.xyz
avm-register.xyz
2 VTTaken DownAngel Drainer
Screenshot of axie-infinits.com
axie-infinits.com
2 VTTaken Down
Screenshot of bitcryptax.pro
bitcryptax.pro
2 VTLive
Screenshot of bitget-index.net
bitget-index.net
2 VTTaken Down
Screenshot of bitpieow.com
bitpieow.com
2 VTTaken Down
Screenshot of bitpierc.com
bitpierc.com
2 VTLive
Screenshot of bitpiern.com
bitpiern.com
2 VTTaken Down
Screenshot of bitpieua.com
bitpieua.com
2 VTTaken Down
Screenshot of bitpieur.com
bitpieur.com
2 VTTaken Down
Screenshot of bitzpie.com
bitzpie.com
2 VTTaken Down
Screenshot of blackmorkie.xyz
blackmorkie.xyz
2 VTTaken Down
Screenshot of blaxbrookven.xyz
blaxbrookven.xyz
2 VTTaken Down
Screenshot of blockdawgclaim.network
blockdawgclaim.network
2 VTTaken DownAngel Drainer
Screenshot of bloxapoxan.xyz
bloxapoxan.xyz
2 VTTaken Down
Screenshot of bonzzy.com
bonzzy.com
2 VTTaken Down
Screenshot of bridgeice.lol
bridgeice.lol
2 VTTaken DownAngel Drainer
Screenshot of buildonhyb.live
buildonhyb.live
2 VTTaken DownAngel Drainer
Screenshot of bullbrute.com
bullbrute.com
2 VTTaken Down
Screenshot of bulldogito.world
bulldogito.world
2 VTTaken DownAngel Drainer
Screenshot of buy-flash-usdt.com
buy-flash-usdt.com
2 VTTaken Down
Screenshot of buy-psyop.org
buy-psyop.org
2 VTTaken Down
Screenshot of bvitpie.com
bvitpie.com
2 VTTaken Down
Screenshot of bybitx.global
bybitx.global
2 VTTaken Down
Screenshot of byk58.com
byk58.com
2 VTTaken Down
Screenshot of bzstverify.cloud
bzstverify.cloud
2 VTTaken Down
Screenshot of calderacapital.xyz
calderacapital.xyz
2 VTTaken Down
Screenshot of calderacapitalgroup.xyz
calderacapitalgroup.xyz
2 VTTaken Down
Screenshot of calderagroup.xyz
calderagroup.xyz
2 VTTaken Down
Screenshot of centricsolmigration.com
centricsolmigration.com
2 VTTaken DownAngel Drainer
Screenshot of cessnetwork.xyz
cessnetwork.xyz
2 VTTaken DownAngel Drainer
Screenshot of chainresolveprotocol.site
chainresolveprotocol.site
2 VTTaken DownAngel Drainer
Screenshot of checker-uxlink.app
checker-uxlink.app
2 VTTaken DownAngel Drainer
Screenshot of claims-eclipse.run
claims-eclipse.run
2 VTTaken DownAngel Drainer
Screenshot of cmctask.live
cmctask.live
2 VTTaken Down
Screenshot of coin-verge.com
coin-verge.com
2 VTTaken Down
Screenshot of coinbixe.com
coinbixe.com
2 VTTaken Down
Screenshot of coins.datahaven.rest
coins.datahaven.rest
2 VTTaken Down
Screenshot of cointo.cloud
cointo.cloud
2 VTTaken DownAngel Drainer
Screenshot of collab-nodes.com
collab-nodes.com
2 VTTaken Down
Screenshot of connect-plasma.to
connect-plasma.to
2 VTTaken Down
Screenshot of copytradingfun.com
copytradingfun.com
2 VTTaken DownAngel Drainer
Screenshot of cosmice.cc
cosmice.cc
2 VTTaken Down
Screenshot of cosmicvpn.net
cosmicvpn.net
2 VTTaken Down
Screenshot of craxproshop.com
craxproshop.com
2 VTTaken Down
Screenshot of cryptobitx.net
cryptobitx.net
2 VTTaken Down
Screenshot of cryptoconnect.tech
cryptoconnect.tech
2 VTTaken Down
Screenshot of csmonly.com
csmonly.com
2 VTTaken Down
Screenshot of csony.com
csony.com
2 VTTaken Down
Screenshot of dapp-rectifier.site
dapp-rectifier.site
2 VTTaken DownAngel Drainer
Screenshot of dappsevmportal.site
dappsevmportal.site
2 VTTaken Down
Screenshot of dappvalidation.com
dappvalidation.com
2 VTTaken DownAngel Drainer
Screenshot of dashboard-nexchain.net
dashboard-nexchain.net
2 VTTaken DownAngel Drainer
« Prev ... 4 5 6 7 8 9 10 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.