Threat Intelligence Dashboard

August 2025 Report

Detailed threat intelligence for 3,788 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

147,432Total Detected
96,489Taken Down
68.8%Kill Rate
92.5%VT Coverage
39,312Abuse Reports
Overview May 262,806 Apr 2615,640 Mar 2618,819 Feb 2642,100 Jan 268,930 Dec 2511,773 Nov 2512,579 Oct 258,841 Sep 257,307 Aug 253,788 Jul 25700 Jun 254
August 2025 Intelligence Report 441.1%
3,788
2,603
Taken Down
1,097
Still Live
68.7%
Kill Rate
5047h
Avg Response
4.3
Avg VT Score

August 2025 saw a dramatic surge in phishing domains with 3,788 detected, marking a 441.1% increase from the previous month. The takedown rate stood at 67.6%, indicating significant operational success, though the mean registrar response time remains critically high at 4426.9 hours. Notably, Kraken and Ledger were heavily targeted, reflecting a strategic focus on cryptocurrency brands. The prevalence of the Angel Drainer kit, implicated in 220 cases, underscores a persistent threat of wallet draining for victims.

  • N/A remains the top abuse registrar with 458 domains, followed by NameSilo, LLC with 224 domains.
  • Targeting of Kraken and Ledger suggests a continued emphasis on cryptocurrency rather than traditional banking.
  • The .com TLD was the most weaponized with 1,828 instances, dwarfing other TLDs like .xyz and .life.
  • The Angel Drainer kit led the pack, posing a significant risk of wallet draining for cryptocurrency users.
  • The majority of phishing infrastructure is hosted in the US with 2,524 domains, indicating a concentration that defenders should prioritize.
  • Despite a takedown rate of 67.6%, the mean registrar response time of 4426.9 hours highlights a critical delay in mitigation efforts.
Outlook
Looking ahead to September 2025, defenders should anticipate continued targeting of cryptocurrency brands, with potential shifts towards new TLDs as attackers diversify. Registrars like N/A and NameSilo, LLC require escalated monitoring due to their high abuse concentrations. Vigilance against the Angel Drainer kit remains crucial to protect users from wallet draining threats.

August 2025 Domains (3,788)

Sorted by VirusTotal detections. Click any domain for full security report.

bestoptionfxts.pro
10 VTLive
bimodal-oxeliteoriginator.web.app
10 VTTaken DownWallet Connect Abuse
binanceflashusdt.info
10 VTTaken Down
bitcoin-exchange-swap.com
10 VTTaken Down
bitget-walletsecurity.xyz
10 VTLiveAngel Drainer
bitgetexchange.app
10 VTLive
bluepointfinancialholdings.pro
10 VTLive
capitalprimeplc.com
10 VTLive
cardano2025.live
10 VTLive
casesbattle.net
10 VTTaken Down
chrome-coinbase-extension.typedream.app
10 VTTaken Down
clearpeak-corebit.com
10 VTLive
coinnodes.xyz
10 VTLiveAngel Drainer
coins-achivas.com
10 VTTaken Down
coinswap.ac
10 VTTaken Down
crypto-wallet-recovery.com
10 VTTaken Down
cs2-skin.com
10 VTLive
curve-fi-dex-faq-en.typedream.app
10 VTTaken Down
daomine.top
10 VTLive
dashboard-qubetics.xyz
10 VTTaken Down
debank.ink
10 VT
dex-support-desk.netlify.app
10 VTTaken DownWallet Connect Abuse
downnew.coinbaseai.bar
10 VTTaken Down
en-welcome-mmetamask-cdn.typedream.app
10 VTTaken Down
exo-wallet.com
10 VTTaken Down
extenson-coinbases.typedream.app
10 VTTaken Down
fameex-login.com
10 VTTaken Down
fastlanex.pro
10 VTLive
fixall-phantomissue.web.app
10 VTTaken Down
frontiercapitalbank.com
10 VTLive
fundacionbuenaventura.cl
10 VTTaken Down
globalfinwallets.live
10 VTLive
grimvaris.pro
10 VTLive
gwax65x.space
10 VTTaken Down
icei000-sasj.top
10 VTTaken Down
jravanoxsigs.click
10 VTLive
jumper.exposed
10 VTTaken DownWallet Connect Abuse
lab-airdrop.xyz
10 VTLiveWallet Connect Abuse
learn--curve-fi-defi.typedream.app
10 VTTaken Down
ledger-live-auth-sso.typedream.app
10 VTTaken Down
ledger.com-secure-live.app
10 VTTaken Down
litecoin-mixers.to
10 VTTaken Down
litecoin-to-usdt.com
10 VTTaken Down
live.ledgerr.us
10 VT
metamskbrowser-faq.typedream.app
10 VTTaken Down
mstoolsnetshop.com
10 VTLive
nanosplusconnect.com
10 VTTaken Down
nbjsdadmin.trust-dash.com
10 VTLive
nesarashiftledger.live
10 VTTaken Down
nodefix-rectify.com
10 VTTaken DownAngel Drainer
pancacefinance.com
10 VTTaken Down
pancake-swap-exchange-us.typedream.app
10 VTTaken Down
perfectonchain.live
10 VTLive
photonbridge.io
10 VTTaken Down
pudgyh.com
10 VTTaken Down
purchase3-blockdag.live
10 VT
qfs-globalledger.com
10 VTLive
queuedappsyc.netlify.app
10 VTTaken Down
raydium-ai-official.firebaseapp.com
10 VTTaken Down
royalmailsexpress.com
10 VTLive
« Prev ... 6 7 8 9 10 11 12 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.