Threat Intelligence Dashboard

August 2025 Report

Detailed threat intelligence for 3,788 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

146,053Total Detected
79,237Taken Down
57%Kill Rate
92.4%VT Coverage
38,873Abuse Reports
Overview May 261,969 Apr 2615,640 Mar 2618,821 Feb 2642,102 Jan 268,930 Dec 2511,773 Nov 2512,579 Oct 258,841 Sep 257,307 Aug 253,788 Jul 25700 Jun 254
August 2025 Intelligence Report 441.1%
3,788
2,139
Taken Down
1,556
Still Live
56.5%
Kill Rate
4877h
Avg Response
4.3
Avg VT Score

August 2025 saw a dramatic surge in phishing domains with 3,788 detected, marking a 441.1% increase from the previous month. The takedown rate stood at 67.6%, indicating significant operational success, though the mean registrar response time remains critically high at 4426.9 hours. Notably, Kraken and Ledger were heavily targeted, reflecting a strategic focus on cryptocurrency brands. The prevalence of the Angel Drainer kit, implicated in 220 cases, underscores a persistent threat of wallet draining for victims.

  • N/A remains the top abuse registrar with 458 domains, followed by NameSilo, LLC with 224 domains.
  • Targeting of Kraken and Ledger suggests a continued emphasis on cryptocurrency rather than traditional banking.
  • The .com TLD was the most weaponized with 1,828 instances, dwarfing other TLDs like .xyz and .life.
  • The Angel Drainer kit led the pack, posing a significant risk of wallet draining for cryptocurrency users.
  • The majority of phishing infrastructure is hosted in the US with 2,524 domains, indicating a concentration that defenders should prioritize.
  • Despite a takedown rate of 67.6%, the mean registrar response time of 4426.9 hours highlights a critical delay in mitigation efforts.
Outlook
Looking ahead to September 2025, defenders should anticipate continued targeting of cryptocurrency brands, with potential shifts towards new TLDs as attackers diversify. Registrars like N/A and NameSilo, LLC require escalated monitoring due to their high abuse concentrations. Vigilance against the Angel Drainer kit remains crucial to protect users from wallet draining threats.

August 2025 Domains (3,788)

Sorted by VirusTotal detections. Click any domain for full security report.

ethereumixer.to
15 VTTaken Down
firstunionbk.com
15 VT
flarenetworkxrp-claim.com
15 VTTaken Down
imtokenam.com
15 VTLive
intholdfinances.com
15 VTTaken Down
ledger-online-wallet.com
15 VTTaken Down
ltc-mixers.to
15 VTTaken Down
metaamaskerlogin.webflow.io
15 VTTaken Down
metropolisfinb.com
15 VTTaken Down
mullvadd.com
15 VTTaken Down
pancakeswap-dex.com
15 VTTaken DownSolana Drainer
phalton.com
15 VTLive
repair-coinbase.com
15 VTTaken Down
roblox.com.gy
15 VTLive
secure-memasklogin.typedream.app
15 VTTaken Down
steam.mmosvc.com
15 VTTaken Down
telegramaem.com
15 VTTaken Down
telegramamr.com
15 VTTaken Down
telegrammun.com
15 VTTaken Down
tonlucky.net
15 VTLive
uniswap.com.co
15 VTTaken Down
validatemain-net.com
15 VTTaken Down
web-extnsion-metmmask.typedream.app
15 VTTaken Down
web-orbliter.fi
15 VTLive
www-safepal.net
15 VTTaken Down
www.50050041.com
15 VTLive
www.evmsecureconnect.com
15 VTTaken Down
www.scfnl.org
15 VTTaken Down
yongzhou.pilot45.com
15 VTTaken Down
zorabridge.app
15 VTLiveWallet Connect Abuse
0pensea.cn
14 VTTaken Down
1ittlepepe.com
14 VTTaken DownAngel Drainer
airdrop-onbasebrian.com
14 VTTaken DownAngel Drainer
amparadapp.live
14 VTTaken Down
appgallery.phantomme.live
14 VTTaken Down
assetscenturybk.com
14 VTLive
bafybeibtcfgrhknlfhnz2c5cddfnsoje4dumrc3wsyoikx2pwuf6fbcsr4.ipfs.dweb.link
14 VTTaken DownWallet Connect Abuse
binance123.com
14 VTTaken Down
binancelink.net
14 VTTaken Down
bitspronix.com
14 VTLive
blockshieldtech.com
14 VTLive
browser-coinbase-xtension.typedream.app
14 VTTaken Down
caixabankeur.com
14 VTTaken Down
captixb.com
14 VTTaken Down
cargo.xtransithaulers.com
14 VTTaken Down
check-amlofficial.com
14 VTTaken Down
claimmemesolana.firebaseapp.com
14 VTLive
coin-qr.to
14 VTLive
cryptocurrency-tumbler.to
14 VTTaken Down
customers-coinbase.com
14 VTLive
dexintegrations.netlify.app
14 VTTaken Down
dogsairdrop.live
14 VTTaken DownWallet Connect Abuse
elite-futurestradinglt.com
14 VTLive
event-wlfi.info
14 VTLive
fortifib.com
14 VTTaken Down
guildcheck.net
14 VTTaken Down
imtokenan.com
14 VTLive
imtokenay.com
14 VTLive
info-debank.com
14 VTTaken Down
kaspawallet.net
14 VTTaken Down
« Prev 1 2 3 4 5 6 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.