Editorial mirrorBrand mentions redacted to public IDs. Hover to inspect. Everything else is theatre.How it works
THE ENABLERS REGISTRYRegistrar accountability archive
Archive LiveRead-only public record · No ads · No tracking
Case file folder with redacted documents and confidential investigation report.
CASE / ANALYTICS

March 2026 Phishing Threat Report — THE ENABLERS REGISTRY Analytics

The Enablers Registry·Editorial mirror·/analytics/

Public record copy. Brand names withheld, public accreditation numbers preserved. If the body below says “we”, that means the original publisher, not this mirror. TER only preserves, redacts, and re-contextualizes.

March 2026 Intelligence Report 49.6%
21,194
13,732
Taken Down
7,322
Still Live
64.8%
Kill Rate
695h
Avg Response
7.3
Avg VT Score
Daily threat detections — March 2026

In March 2026, THE ENABLERS REGISTRY detected 21,194 possibly phishing domains, a 49.6% decrease from February. 13,732 of them (64.8%) have already been neutralized, while 7,322 remain live and under active escalation. The most abused registrar was [REDACTED] with 4,836 malicious domains, followed by [REDACTED] (4,032). Attackers targeted [REDACTED] hardest, with FinCEN MSB #31000023456789 a close second.

  • [REDACTED] alone accounts for 22.8% of the month's detections (4,836 domains) — concentration this high indicates systematic abuse, not random sign-ups.
  • Brand pressure is concentrated on [REDACTED] and FinCEN MSB #310000234567891,906 lookalike domains between them.
  • The .com TLD leads with 7,160 malicious registrations, ahead of .dev (3,810).
  • Dominant drainer kit: Solana Drainer (198 deployments detected).
  • Average infrastructure response time: 695h — well beyond any reasonable takedown window.
Outlook
Heading into April 2026, expect continued pressure on [REDACTED] users; registrations via [REDACTED] remain the primary vector to watch, with Solana Drainer kits still circulating. Full evidence for every domain is published in the public destroylist.

March 2026 Domains (21,194)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of [REDACTED]
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
[REDACTED]
3 VTTaken Down
Screenshot of agenc.pumpvote.us
agenc.pumpvote.us
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of airdrop-live.cfd
airdrop-live.cfd
3 VTTaken Down
Screenshot of airdrop-online.bond
airdrop-online.bond
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
Screenshot of airdrop.fight.foundation
airdrop.fight.foundation
3 VTLive
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
[REDACTED]
3 VTTaken Down
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
[REDACTED]
3 VTLive
Screenshot of alfabez.eu
alfabez.eu
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
[REDACTED]
3 VTLive
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of allocation-suilend.fit
allocation-suilend.fit
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of allocation-suilend.qpon
allocation-suilend.qpon
3 VTTaken Down
Screenshot of allocation-suilend.rest
allocation-suilend.rest
3 VTTaken Down
Screenshot of allocation-suilend.sbs
allocation-suilend.sbs
3 VTTaken Down
Screenshot of allocation-suilend.wiki
allocation-suilend.wiki
3 VTTaken Down
Screenshot of allocation-suliend.buzz
allocation-suliend.buzz
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of allocation-suliend.lol
allocation-suliend.lol
3 VTTaken Down
Screenshot of allocation-suliend.pw
allocation-suliend.pw
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of allocatlon-suilend.lol
allocatlon-suilend.lol
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of allocatlon-suliend.cfd
allocatlon-suliend.cfd
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
ambulatorio-veterinario-parco-monta.it
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTLive
Screenshot of [REDACTED]
[REDACTED]
3 VTTaken Down

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Continue browsing the ledger

This page is the editorial mirror. Brand names are redacted to public IANA / business identifiers. Use the index to navigate other case files.

Open registrar ledger → All briefings