Threat Intelligence Dashboard

September 2025 Report

Detailed threat intelligence for 7,306 phishing domains. Registrar abuse, drainer kits, targeted brands, and AI-generated expert assessment.

166,629Total Detected
144,237Taken Down
91.7%Kill Rate
93.5%VT Coverage
45,506Abuse Reports
Overview Jun 268,101 May 267,021 Apr 2615,633 Mar 2618,814 Feb 2642,095 Jan 268,924 Dec 2511,773 Nov 2512,578 Oct 258,841 Sep 257,306 Aug 253,788 Jul 25700 Jun 253
September 2025 Intelligence Report 92.9%
7,306
6,984
Taken Down
182
Still Live
95.6%
Kill Rate
4783h
Avg Response
4.7
Avg VT Score

In September 2025, PhishDestroy detected <strong>7,307</strong> phishing domains, marking a <strong>92.9%</strong> increase from the previous month, with a significant surge in activity on September 20th. The operational impact was notable with a takedown rate of <strong>82.2%</strong>, although the mean registrar response time remained high at <strong>3,828.5</strong> hours. Attackers continued to focus on the crypto sector, with <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> as top targets, indicating a shift in targeting tactics. The dominance of the <strong>Angel Drainer</strong> kit suggests a persistent threat of wallet draining and seed theft for victims.

  • <strong>N/A</strong> leads in registrar abuse with <strong>819</strong> domains, followed closely by <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong> with <strong>721</strong> domains.
  • Crypto brands like <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> were heavily targeted, overshadowing traditional sectors like banking.
  • The <strong>.com</strong> TLD remains the most weaponized with <strong>2,561</strong> domains, while <strong>.xyz</strong> and <strong>.live</strong> show growing abuse.
  • The <strong>Angel Drainer</strong> kit was used in <strong>1,120</strong> incidents, indicating a focus on wallet draining and seed theft.
  • The US hosts the majority of phishing infrastructure with <strong>5,931</strong> domains, but there is notable activity in <strong>Germany</strong> and <strong>Netherlands</strong>.
  • Detection-to-takedown efficiency remains challenged with a mean response time of <strong>3,828.5</strong> hours, necessitating faster registrar actions.
Outlook
Expect continued emphasis on crypto-targeted phishing, with potential diversification in drainer kit variants. Watch for increased activity from registrars like <strong>N/A</strong> and <strong>NICENIC INTERNATIONAL GROUP CO., LIMITED</strong>, which may require escalation. Defenders should prepare for heightened phishing activity around key crypto events and ensure rapid response capabilities.

September 2025 Domains (7,306)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of mdsoft-crypt.web.app
mdsoft-crypt.web.app
15 VTTaken Down
Screenshot of metaeth.cc
metaeth.cc
15 VTTaken Down
Screenshot of metamask-logii.pineapple.page
metamask-logii.pineapple.page
15 VT
Screenshot of metamask-wallet.to
metamask-wallet.to
15 VTTaken Down
Screenshot of metamaskloeegin.w3spaces.com
metamaskloeegin.w3spaces.com
15 VTTaken Down
Screenshot of metamaskuk.cc
metamaskuk.cc
15 VTTaken Down
Screenshot of mytamasklogen.webflow.io
mytamasklogen.webflow.io
15 VTTaken Down
Screenshot of noox.fi
noox.fi
15 VTTaken DownWallet Connect Abuse
Screenshot of nooxdao.top
nooxdao.top
15 VTTaken DownWallet Connect Abuse
Screenshot of official-ledger.live
official-ledger.live
15 VTTaken Down
Screenshot of okxplay.com
okxplay.com
15 VTTaken Down
Screenshot of p0.fsoall.ir
p0.fsoall.ir
15 VT
Screenshot of paijkcakeswap.com
paijkcakeswap.com
15 VTTaken DownAngel Drainer
Screenshot of paikecakeswap.com
paikecakeswap.com
15 VTTaken DownAngel Drainer
Screenshot of pasxfful.com
pasxfful.com
15 VTTaken Down
Screenshot of portal.openledgerhq.click
portal.openledgerhq.click
15 VTTaken Down
Screenshot of pswap.flnanceconnect.app
pswap.flnanceconnect.app
15 VTTaken DownAngel Drainer
Screenshot of pythop.com
pythop.com
15 VTTaken Down
Screenshot of qbointuit.app
qbointuit.app
15 VTTaken Down
Screenshot of rabby-app.com
rabby-app.com
15 VTTaken Down
Screenshot of remote.login-coinbase-secured.com
remote.login-coinbase-secured.com
15 VTTaken Down
Screenshot of rexas-token.xyz
rexas-token.xyz
15 VTTaken DownAngel Drainer
Screenshot of same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app
same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app
15 VTTaken Down
Screenshot of simpleswap-io.to
simpleswap-io.to
15 VTTaken Down
Screenshot of stakewlfi.top
stakewlfi.top
15 VTTaken Down
Screenshot of stlink.world
stlink.world
15 VTTaken DownWallet Connect Abuse
Screenshot of swap.web-1inch.to
swap.web-1inch.to
15 VTTaken Down
Screenshot of tokenpocket.hk.cn
tokenpocket.hk.cn
15 VTTaken Down
Screenshot of tpwallct.com
tpwallct.com
15 VTTaken Down
Screenshot of trezor-suite.co.com
trezor-suite.co.com
15 VTTaken Down
Screenshot of v1-ledger.live
v1-ledger.live
15 VTTaken Down
Screenshot of v2-ledger.live
v2-ledger.live
15 VTTaken Down
Screenshot of v3-open-sea-opensea-nft-marketplace.net
v3-open-sea-opensea-nft-marketplace.net
15 VTTaken Down
Screenshot of v4-ledger.live
v4-ledger.live
15 VTTaken Down
Screenshot of virtualstake.app
virtualstake.app
15 VTTaken DownAngel Drainer
Screenshot of wallet-assist-desk.app
wallet-assist-desk.app
15 VTTaken Down
Screenshot of wallet.web-rabby.to
wallet.web-rabby.to
15 VTTaken Down
Screenshot of wallet.web-solflare.to
wallet.web-solflare.to
15 VTTaken Down
Screenshot of walletpinet.com
walletpinet.com
15 VTTaken Down
Screenshot of web-coinbase-com-auth.pineapple.page
web-coinbase-com-auth.pineapple.page
15 VT
Screenshot of web-coinbase-comm.pineapple.page
web-coinbase-comm.pineapple.page
15 VTTaken Down
Screenshot of web-rabby.to
web-rabby.to
15 VTTaken Down
Screenshot of welcome-ledgaer-com.netlify.app
welcome-ledgaer-com.netlify.app
15 VTTaken Down
Screenshot of wlfi-unlock-box.com
wlfi-unlock-box.com
15 VTTaken DownAngel Drainer
Screenshot of wollrdllberteyflnanclale.info
wollrdllberteyflnanclale.info
15 VTTaken DownAngel Drainer
Screenshot of worldliberltyfinancial.com
worldliberltyfinancial.com
15 VTTaken DownAngel Drainer
Screenshot of www.wlfidesktop.app
www.wlfidesktop.app
15 VTTaken Down
Screenshot of www.worldquantumfinance.com
www.worldquantumfinance.com
15 VTTaken Down
Screenshot of www.zkswap.fun
www.zkswap.fun
15 VTTaken Down
Screenshot of yardim.sbs
yardim.sbs
15 VTTaken Down
Screenshot of zerano.cc
zerano.cc
15 VTTaken Down
Screenshot of 08pf.cn
08pf.cn
14 VTTaken Down
Screenshot of 1inch.4everland.app
1inch.4everland.app
14 VTTaken Down
Screenshot of 1ylm.com.cn
1ylm.com.cn
14 VTTaken Down
Screenshot of aethir-2-20mr.4everland.app
aethir-2-20mr.4everland.app
14 VTTaken Down
Screenshot of aml-sector.world
aml-sector.world
14 VTTaken Down
Screenshot of amlcheck.in
amlcheck.in
14 VTTaken DownWallet Connect Abuse
Screenshot of anniversary-ethereum.com
anniversary-ethereum.com
14 VTTaken DownAngel Drainer
Screenshot of apex-advisors.pro
apex-advisors.pro
14 VTTaken Down
Screenshot of app-jup.ag
app-jup.ag
14 VTTaken Down
« Prev 1 2 3 4 5 6 7 ... Next »

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Explore More

Related intelligence pages and data feeds.