Editorial mirrorBrand mentions redacted to public IDs. Hover to inspect. Everything else is theatre.How it works
THE ENABLERS REGISTRYRegistrar accountability archive
Archive LiveRead-only public record · No ads · No tracking
Case file folder with redacted documents and confidential investigation report.
CASE / ANALYTICS

September 2025 Phishing Threat Report — THE ENABLERS REGISTRY Analytics

The Enablers Registry·Editorial mirror·/analytics/

Public record copy. Brand names withheld, public accreditation numbers preserved. If the body below says “we”, that means the original publisher, not this mirror. TER only preserves, redacts, and re-contextualizes.

September 2025 Intelligence Report 92.9%
7,304
6,074
Taken Down
1,186
Still Live
83.2%
Kill Rate
4786h
Avg Response
4.9
Avg VT Score

In September 2025, THE ENABLERS REGISTRY detected <strong>7,307</strong> possibly phishing domains, marking a <strong>92.9%</strong> increase from the previous month, with a significant surge in activity on September 20th. The operational impact was notable with a takedown rate of <strong>82.2%</strong>, although the mean registrar response time remained high at <strong>3,828.5</strong> hours. Attackers continued to focus on the crypto sector, with <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> as top targets, indicating a shift in targeting tactics. The dominance of the <strong>Angel Drainer</strong> kit suggests a persistent threat of wallet draining and seed theft for victims.

  • <strong>N/A</strong> leads in registrar abuse with <strong>819</strong> domains, followed closely by <strong>[REDACTED]</strong> with <strong>721</strong> domains.
  • Crypto brands like <strong>Generic Crypto</strong> and <strong>SushiSwap</strong> were heavily targeted, overshadowing traditional sectors like banking.
  • The <strong>.com</strong> TLD remains the most weaponized with <strong>2,561</strong> domains, while <strong>.xyz</strong> and <strong>.live</strong> show growing abuse.
  • The <strong>Angel Drainer</strong> kit was used in <strong>1,120</strong> incidents, indicating a focus on wallet draining and seed theft.
  • The US hosts the majority of possibly phishing infrastructure with <strong>5,931</strong> domains, but there is notable activity in <strong>Germany</strong> and <strong>Netherlands</strong>.
  • Detection-to-takedown efficiency remains challenged with a mean response time of <strong>3,828.5</strong> hours, necessitating faster registrar actions.
Outlook
Expect continued emphasis on crypto-targeted possibly phishing, with potential diversification in drainer kit variants. Watch for increased activity from registrars like <strong>N/A</strong> and <strong>[REDACTED]</strong>, which may require escalation. Defenders should prepare for heightened possibly phishing activity around key crypto events and ensure rapid response capabilities.

September 2025 Domains (7,304)

Sorted by VirusTotal detections. Click any domain for full security report.

Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of claimsfreebox.lat
claimsfreebox.lat
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of clanker.sushiswap.cyou
clanker.sushiswap.cyou
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of colend.sushiswap.onl
colend.sushiswap.onl
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken DownAngel Drainer
Screenshot of confidentiallayer.quest
confidentiallayer.quest
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken DownAngel Drainer
Screenshot of contango.sushi.baby
contango.sushi.baby
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken DownAngel Drainer
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of cvc.sushiswap.onl
cvc.sushiswap.onl
Taken DownAngel Drainer
Screenshot of [REDACTED]
[REDACTED]
Taken DownSolana Drainer
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of dashboard.acrodrome.financial
dashboard.acrodrome.financial
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Live
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of defnlayiiagreeable.lol
defnlayiiagreeable.lol
Taken DownSolana Drainer
Screenshot of dexe.sushis.dev
dexe.sushis.dev
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of dino.sushiswap.buzz
dino.sushiswap.buzz
Taken Down
Screenshot of dog.sushiswap.onl
dog.sushiswap.onl
Taken Down
Screenshot of doge-sushi.cfd
doge-sushi.cfd
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of dood.sushi.baby
dood.sushi.baby
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of draineragency.sol.build
draineragency.sol.build
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken DownIce Possibly phishing
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of early-magnify.cash
early-magnify.cash
Taken Down
Screenshot of earnify-agency.co.ke
earnify-agency.co.ke
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken DownAngel Drainer
Screenshot of edge.sushi.baby
edge.sushi.baby
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of edge.sushiswap.buzz
edge.sushiswap.buzz
Taken Down
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken DownAngel Drainer
Screenshot of egl1.sushiswap.lol
egl1.sushiswap.lol
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down
Screenshot of eigen.sushiswap.cyou
eigen.sushiswap.cyou
Taken Down
Screenshot of eigen.sushiswap.lol
eigen.sushiswap.lol
Taken Down
Screenshot of [REDACTED]
[REDACTED]
Taken Down

Detection Trends

Monthly domain volume, kill rate, and live threats over time.

Monthly Detected Domains

Kill Rate %

Continue browsing the ledger

This page is the editorial mirror. Brand names are redacted to public IANA / business identifiers. Use the index to navigate other case files.

Open registrar ledger → All briefings