Threat Intelligence Dashboard

July 2025 Report

Detailed threat intelligence for 700 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,600Total Detected
144,147Taken Down
91.6%Kill Rate
93.5%VT Coverage
45,500Abuse Reports
Overview Jun 268,072 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
July 2025 Intelligence Report 23233.3%
700
663
Taken Down
17
Still Live
94.7%
Kill Rate
6384h
Avg Response
4.3
Avg VT Score

In July 2025, PhishDestroy detected <strong>700</strong> phishing domains, marking a <strong>17400.0%</strong> increase from the previous month, with a takedown rate of <strong>85.1%</strong>. Notably, <strong>Angel Drainer</strong> kits were identified on <strong>183</strong> domains, posing significant risks of wallet drains and seed theft. The mean registrar response time was a concerning <strong>4981.9</strong> hours, highlighting gaps in takedown efficiency. Despite the high volume, our operational impact remains strong with a substantial number of domains taken offline, though registrar responsiveness needs improvement.

  • <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> lead in registrar abuse with <strong>75</strong> and <strong>71</strong> domains respectively, indicating a need for targeted mitigation.
  • Crypto brands remain prime targets with <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> being the most attacked, suggesting a persistent focus on digital asset theft.
  • The <strong>.com</strong> TLD is the most weaponized with <strong>304</strong> domains, followed by <strong>.xyz</strong> with <strong>84</strong>, indicating a preference for these TLDs in phishing campaigns.
  • The dominance of <strong>Angel Drainer</strong> kits across <strong>183</strong> domains suggests a prevalent threat of wallet drains and seed theft.
  • The US hosts the majority of phishing infrastructure with <strong>561</strong> domains, indicating a concentration of malicious activities in this region.
  • The mean detection-to-takedown time remains high at <strong>4981.9</strong> hours, necessitating faster registrar responses to reduce active phishing threats.
Outlook
Given the surge in phishing domains and the focus on crypto brands, defenders should prioritize monitoring for <strong>Angel Drainer</strong> kits and .com TLDs. Registrars like <strong>NameSilo, LLC</strong> and <strong>PDR Ltd.</strong> require escalation to enhance response times. Expect continued targeting of crypto sectors, necessitating heightened vigilance and rapid takedown actions.

July 2025 Domains (700)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of connectwallapp.com
connectwallapp.com
18 VTTaken Down
Screenshot of pubgzh-cn.top
pubgzh-cn.top
18 VTTaken Down
Screenshot of ff-info-online.com
ff-info-online.com
17 VTTaken Down
Screenshot of 9823712-coinbase.com
9823712-coinbase.com
16 VTTaken Down
Screenshot of flr-portal.org
flr-portal.org
16 VTTaken Down
Screenshot of https-dotus.com
https-dotus.com
16 VTTaken Down
Screenshot of p2pwithpi.com
p2pwithpi.com
16 VTTaken Down
Screenshot of pancakeswapsfi.org
pancakeswapsfi.org
16 VTTaken DownSolana Drainer
Screenshot of coinbase003.xyz
coinbase003.xyz
15 VTTaken Down
Screenshot of foundation-ethereum.com
foundation-ethereum.com
15 VTTaken Down
Screenshot of imtokenu.com
imtokenu.com
15 VTTaken Down
Screenshot of pagesvalidation.com
pagesvalidation.com
15 VTTaken Down
Screenshot of assetspacifics.ltd
assetspacifics.ltd
14 VTTaken Down
Screenshot of cssats.com
cssats.com
14 VTTaken DownInferno Drainer
Screenshot of dappradarco.com
dappradarco.com
14 VTTaken Down
Screenshot of followxpert.com
followxpert.com
14 VTTaken Down
Screenshot of inter-pinetprofile.com
inter-pinetprofile.com
14 VT
Screenshot of nftminter.xyz
nftminter.xyz
14 VTTaken Down
Screenshot of p2pmainnetapp.com
p2pmainnetapp.com
14 VTTaken Down
Screenshot of p2ppayment-livetrade.com
p2ppayment-livetrade.com
14 VTTaken Down
Screenshot of pi-marketpayment.com
pi-marketpayment.com
14 VTTaken Down
Screenshot of pii-con.com
pii-con.com
14 VTTaken Down
Screenshot of abhienergetic.com
abhienergetic.com
13 VTTaken Down
Screenshot of boomcapital-investments.com
boomcapital-investments.com
13 VTTaken Down
Screenshot of crest-cridetunion.com
crest-cridetunion.com
13 VTTaken Down
Screenshot of cryptoaml.bot
cryptoaml.bot
13 VTTaken DownWallet Connect Abuse
Screenshot of decentrastake.com
decentrastake.com
13 VTTaken Down
Screenshot of guardawebwallet.com
guardawebwallet.com
13 VTTaken Down
Screenshot of okx-listings.com
okx-listings.com
13 VTTaken Down
Screenshot of opulenttrade-invests.com
opulenttrade-invests.com
13 VTTaken Down
Screenshot of p2p-relocke.com
p2p-relocke.com
13 VTTaken Down
Screenshot of quickdashxpress.com
quickdashxpress.com
13 VTTaken Down
Screenshot of adelphilbanplc.com
adelphilbanplc.com
12 VTTaken Down
Screenshot of bitgrex.com
bitgrex.com
12 VTTaken Down
Screenshot of bitpieon.com
bitpieon.com
12 VTTaken Down
Screenshot of bnceex.com
bnceex.com
12 VTTaken Down
Screenshot of bridgedapp.nl
bridgedapp.nl
12 VTTaken DownAngel Drainer
Screenshot of cookie-sushi.xyz
cookie-sushi.xyz
12 VTTaken Down
Screenshot of crest-crditunion.com
crest-crditunion.com
12 VTTaken Down
Screenshot of dappsync.sharepool.in
dappsync.sharepool.in
12 VTTaken DownAngel Drainer
Screenshot of ff-exchange.art
ff-exchange.art
12 VTTaken Down
Screenshot of nodeapp-serverlaunch.com
nodeapp-serverlaunch.com
12 VTTaken DownWallet Connect Abuse
Screenshot of 6npool9s.top
6npool9s.top
11 VTTaken Down
Screenshot of active-exchange.pro
active-exchange.pro
11 VTTaken Down
Screenshot of caw-sushi.pro
caw-sushi.pro
11 VTTaken Down
Screenshot of cb-loginportal.cloud
cb-loginportal.cloud
11 VTTaken DownAngel Drainer
Screenshot of claimseclipse.xyz
claimseclipse.xyz
11 VTTaken DownAngel Drainer
Screenshot of communitycreatordev.com
communitycreatordev.com
11 VTTaken Down
Screenshot of core-infop2p.com
core-infop2p.com
11 VTTaken Down
Screenshot of dapp.sharepool.in
dapp.sharepool.in
11 VTTaken DownAngel Drainer
Screenshot of fenolex.com
fenolex.com
11 VTTaken Down
Screenshot of fil-sushi.pro
fil-sushi.pro
11 VTTaken DownAngel Drainer
Screenshot of flarenetwork-xrp.finance
flarenetwork-xrp.finance
11 VTTaken Down
Screenshot of greenarklogistic.com
greenarklogistic.com
11 VTTaken Down
Screenshot of holddex.icu
holddex.icu
11 VTTaken Down
Screenshot of hyperliquidtrade.link
hyperliquidtrade.link
11 VTTaken DownAngel Drainer
Screenshot of inj-sushi.pro
inj-sushi.pro
11 VTTaken DownAngel Drainer
Screenshot of intlcargo-express.com
intlcargo-express.com
11 VTTaken Down
Screenshot of issuesfixing.pro
issuesfixing.pro
11 VTTaken Down
Screenshot of neural-sushi.xyz
neural-sushi.xyz
11 VTTaken DownAngel Drainer
1 2 3 4 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.