Threat Intelligence Dashboard

September 2025 Report

Detailed threat intelligence for 7,307 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

149,349Total Detected
107,057Taken Down
75.6%Kill Rate
92.5%VT Coverage
39,811Abuse Reports
Overview May 263,637 Apr 2615,640 Mar 2618,819 Feb 2642,098 Jan 268,930 Dec 2511,773 Nov 2512,579 Oct 258,841 Sep 257,307 Aug 253,788 Jul 25700 Jun 254
September 2025 Intelligence Report 92.9%
7,307
5,259
Taken Down
1,923
Still Live
72%
Kill Rate
4533h
Avg Response
4.7
Avg VT Score

In September 2025, PhishDestroy detected 7,307 phishing domains, marking a 92.9% increase from the previous month, with a significant surge in activity on September 20th. The operational impact was notable with a takedown rate of 82.2%, although the mean registrar response time remained high at 3,828.5 hours. Attackers continued to focus on the crypto sector, with Generic Crypto and SushiSwap as top targets, indicating a shift in targeting tactics. The dominance of the Angel Drainer kit suggests a persistent threat of wallet draining and seed theft for victims.

  • N/A leads in registrar abuse with 819 domains, followed closely by NICENIC INTERNATIONAL GROUP CO., LIMITED with 721 domains.
  • Crypto brands like Generic Crypto and SushiSwap were heavily targeted, overshadowing traditional sectors like banking.
  • The .com TLD remains the most weaponized with 2,561 domains, while .xyz and .live show growing abuse.
  • The Angel Drainer kit was used in 1,120 incidents, indicating a focus on wallet draining and seed theft.
  • The US hosts the majority of phishing infrastructure with 5,931 domains, but there is notable activity in Germany and Netherlands.
  • Detection-to-takedown efficiency remains challenged with a mean response time of 3,828.5 hours, necessitating faster registrar actions.
Outlook
Expect continued emphasis on crypto-targeted phishing, with potential diversification in drainer kit variants. Watch for increased activity from registrars like N/A and NICENIC INTERNATIONAL GROUP CO., LIMITED, which may require escalation. Defenders should prepare for heightened phishing activity around key crypto events and ensure rapid response capabilities.

September 2025 Domains (7,307)

Sorted by VirusTotal detections. Click any domain for full security report.

asterdex.com.co
Live
asterdex.pw
LiveWallet Connect Abuse
atom.sushi.us.com
LiveAngel Drainer
aura.sushis.ninja
LiveAngel Drainer
autodiscover.ledgerhardwarerun.com
Taken Down
avaxbonus.com
Taken Down
avaxcollect.com
Live
axiomtrade.co
Taken Down
babylon.sushi.us.com
LiveAngel Drainer
backupvault.online
Live
bad.sushiswap.onl
LiveAngel Drainer
bafybeia5w6ij6k5e2i3vwagaacosirdjz6kce4q3y2thlqdaqcfnictzmu.ipfs.dweb.link
Taken Down
banana.sushiswap.best
Taken Down
bankssolution.ng
Taken Down
bearish.run
Taken Down
bedrock.sushiswap.buzz
Taken Down
bedrock.sushiswap.onl
Taken Down
beefy.sushi.us.com
LiveAngel Drainer
beepfun.world
Taken Down
beets.sushis.ninja
Taken DownAngel Drainer
benqiapp.live
Live
beraborrow.world
Taken Down
berobit.com
Taken Down
bestukauctions.co.uk
Taken Down
bigbrotip.com
Taken DownSolana Drainer
biggestbrodontflag.com
Taken DownSolana Drainer
bigremopour.com
Taken DownSolana Drainer
bingex.org
Taken Down
biocoin-x.trade
Taken DownSolana Drainer
bitcoindady.com
Live
bitcoinpenguins.livechainx.xyz
Taken DownAngel Drainer
bitcpro.live
Taken Down
bitgetreferralcode.site
Taken Down
bitmefo.com
Live
bitrumi.com
Taken Down
bitsplay.bet
Taken Down
bitsurg.com
Taken Down
bittensor.sushis.ninja
LiveAngel Drainer
bitzori.com
Live
black.sushi.us.com
Taken Down
block-gptfi.us
Live
block-scan.pro
Taken DownWallet Connect Abuse
block3.claims
Taken Down
blockchainstoken.web.app
Taken Down
blockdag-network-en.web.app
LiveWallet Connect Abuse
blog.valorantmobile.fr
Taken Down
bloxflip.com
Taken Down
bluebeanjon.com
Taken DownSolana Drainer
bmbera.club
Taken Down
bndx.world
Taken Down
bonk-airdrop.live
Taken Down
bonk-token.world
Taken DownSolana Drainer
borroefiv2.com
Taken Down
botfiapp.org
Taken Down
boundlessproofs.com
Taken Down
bridge-v2-dapp-testnet.apertum.io
Taken Down
broccoli.sushiswap.one
Taken Down
btc-asia.net
Live
btcbull.sushiswap.best
Taken Down
btcbull.sushiswap.it.com
Taken Down

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.