Overview
Aug 269,225
Jul 2618,429
Jun 2622,732
May 267,405
Apr 2616,732
Mar 2620,981
Feb 2640,388
Jan 268,919
Dec 2511,740
Nov 2512,563
Oct 258,835
Sep 257,297
Aug 253,782
Jul 25700
Jun 253
July 2025 Intelligence Report
23233.3%
700
470
Taken Down
186
Still Live
67.1%
Kill Rate
6390h
Avg Response
5.1
Avg VT Score
In July 2025, PhishDestroy detected 700 phishing domains, a 23233.3% increase from June. 470 of them (67.1%) have already been neutralized, while 190 remain live and under active escalation. The most abused registrar was Web Commerce Communications Limited with 85 malicious domains, followed by NameSilo, LLC (78). Attackers targeted across hardest, with Ethereum a close second.
- Web Commerce Communications Limited alone accounts for 12.1% of the month's detections (85 domains) — concentration this high indicates systematic abuse, not random sign-ups.
- Brand pressure is concentrated on across and Ethereum — 112 lookalike domains between them.
- The .com TLD leads with 304 malicious registrations, ahead of .xyz (84).
- Dominant drainer kit: Angel Drainer (179 deployments detected).
- Average infrastructure response time: 6390h — well beyond any reasonable takedown window.
Outlook
Heading into August 2025, expect continued pressure on across users; registrations via Web Commerce Communications Limited remain the primary vector to watch, with Angel Drainer kits still circulating. Full evidence for every domain is published in the public destroylist.
Top Registrars
Active Drainer Kits
July 2025 Domains (700)
Sorted by VirusTotal detections. Click any domain for full security report.
Detection Trends
Monthly domain volume, kill rate, and live threats over time.
Monthly Detected Domains
Kill Rate %
Explore More
Related intelligence pages and data feeds.



























































