Threat Intelligence Dashboard

August 2025 Report

Detailed threat intelligence for 3,788 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

148,969Total Detected
100,736Taken Down
71.2%Kill Rate
92.5%VT Coverage
39,720Abuse Reports
Overview May 263,461 Apr 2615,640 Mar 2618,819 Feb 2642,098 Jan 268,930 Dec 2511,773 Nov 2512,579 Oct 258,841 Sep 257,307 Aug 253,788 Jul 25700 Jun 254
August 2025 Intelligence Report 441.1%
3,788
2,558
Taken Down
1,142
Still Live
67.5%
Kill Rate
5102h
Avg Response
4.3
Avg VT Score

August 2025 saw a dramatic surge in phishing domains with 3,788 detected, marking a 441.1% increase from the previous month. The takedown rate stood at 67.6%, indicating significant operational success, though the mean registrar response time remains critically high at 4426.9 hours. Notably, Kraken and Ledger were heavily targeted, reflecting a strategic focus on cryptocurrency brands. The prevalence of the Angel Drainer kit, implicated in 220 cases, underscores a persistent threat of wallet draining for victims.

  • N/A remains the top abuse registrar with 458 domains, followed by NameSilo, LLC with 224 domains.
  • Targeting of Kraken and Ledger suggests a continued emphasis on cryptocurrency rather than traditional banking.
  • The .com TLD was the most weaponized with 1,828 instances, dwarfing other TLDs like .xyz and .life.
  • The Angel Drainer kit led the pack, posing a significant risk of wallet draining for cryptocurrency users.
  • The majority of phishing infrastructure is hosted in the US with 2,524 domains, indicating a concentration that defenders should prioritize.
  • Despite a takedown rate of 67.6%, the mean registrar response time of 4426.9 hours highlights a critical delay in mitigation efforts.
Outlook
Looking ahead to September 2025, defenders should anticipate continued targeting of cryptocurrency brands, with potential shifts towards new TLDs as attackers diversify. Registrars like N/A and NameSilo, LLC require escalated monitoring due to their high abuse concentrations. Vigilance against the Angel Drainer kit remains crucial to protect users from wallet draining threats.

August 2025 Domains (3,788)

Sorted by VirusTotal detections. Click any domain for full security report.

classe2025.fr
12 VTLive
coin-qrs.to
12 VTTaken Down
conecwinlab.com.winpopcach.com
12 VTLive
credit.starlngs.com
12 VTLive
criptomixer.io
12 VTLive
czbnb.bet
12 VTTaken Down
defil-lama.github.io
12 VTTaken Down
ecobrokercapital.com
12 VTLive
fastmovedeliverycompany.com
12 VTTaken Down
financeprimes.com
12 VTLive
finosagebank.com
12 VTLive
firme-bitline.com
12 VTTaken Down
firmtradex.icu
12 VTLive
flrclaimreserve.live
12 VTTaken Down
flrconnectportal.live
12 VTTaken DownIce Phishing
genesisicu.com
12 VTLive
glovesinvest.com
12 VTLive
halaaitradingbot.com
12 VTLive
heusdc.com
12 VTTaken Down
kucoinporl.com
12 VTTaken Down
layerchain.net.ng
12 VTTaken Down
ledger-report.com
12 VTTaken Down
ledger-walletlink.com
12 VT
littlepepo.com
12 VTLiveAngel Drainer
metasingle.id
12 VTLive
orbix-finance.com
12 VTTaken Down
paxosgift.com
12 VTTaken DownWallet Connect Abuse
qubeticsresolve.com
12 VTTaken Down
rainbowaz.com
12 VTTaken Down
safe.pal-extension.cc
12 VTTaken Down
sentineledgesb.com
12 VTTaken Down
seurefastdigital.com
12 VTTaken Down
steamcommunityn.asia
12 VTTaken Down
swapzone.exchange
12 VTLive
swift-oxygen-wide.on-fleek.app
12 VTTaken Down
texabaycu.com
12 VTTaken Down
trustaxisbnk.com
12 VTTaken Down
trustwalletcustomerservice.org
12 VTTaken Down
wallet-authenticator.live
12 VTTaken Down
walletconnectchain.web.app
12 VTTaken Down
wh468304.ispot.cc
12 VTTaken DownAngel Drainer
wild-beta-car.com
12 VTTaken Down
www.acbdegf.pilot45.com
12 VTTaken Down
www.holddex.com
12 VTTaken Down
www.opensea.26569.zettinc.com
12 VTTaken DownAngel Drainer
www.zircuito.com
12 VTTaken Down
xslots.world
12 VTTaken Down
zenafex.com
12 VTLiveWallet Connect Abuse
1-slots.world
11 VTLive
alcon-share.com
11 VTTaken Down
amexcapital.org
11 VTTaken Down
apexcryptocurrencytrading.com
11 VTTaken Down
aramexship.com
11 VTTaken Down
atomicdesktopwallet.com
11 VTTaken Down
attserverqa1.weebly.com
11 VT
axiscapitalsholdings.com
11 VTTaken Down
bafybeias5wqpscrcyqj7vhsimyzrc525wc7s4kqab32qatjxhqsngdqvzy.ipfs.dweb.link
11 VTTaken Down
bibbydivs.com
11 VTLive
bifex.cc
11 VTLive
bimodal-oxeliteoriginator.firebaseapp.com
11 VTTaken DownWallet Connect Abuse
« Prev ... 3 4 5 6 7 8 9 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.