Malicious websites today

6,107

Malicious websites this week

1,740,223

Malicious websites this month

4,410,958

Total malicious websites

17,678,771

TLD distribution

  • .com - 51.6%
  • .top - 16.0%
  • .xyz - 9.6%
  • .cc - 6.3%
  • .shop - 3.3%
  • .buzz - 3.2%
  • .net - 3.2%
  • .cn - 2.7%
  • .org - 2.3%
  • .info - 1.9%

Threat trend

13.4M14.8M16.2M17.7M
Threats
07/0713/0719/0724/0730/0705/08

Recent threats

  • https://searchhub.icu

    https://searchhub.icu

    Risk score10/10Aug 04, 2026
    • The website advertises a data platform that allows searching for personal information of Discord users, including over 8.2 billion messages, user profiles, voice sessions, and uploaded files, which is a clear sign of unauthorized data collection and sale.
    • This service also provides the ability to search for FiveM player information, licenses, and identifiers, indicating the purpose of tracking and identifying users across multiple platforms without their consent.
  • https://napthex5.net

    https://napthex5.net

    Risk score9/10Aug 04, 2026
    • The domain name napthex5.net was recently registered on July 25, 2025, indicating that it is a relatively new domain, often used by scam websites to avoid detection and being flagged as malicious.
    • The domain has a short registration period, lasting only until July 25, 2027, which is a common characteristic of scam websites that operate for a short time and then disappear.
  • https://tokhaiyte.vn

    https://tokhaiyte.vn

    Risk score10/10Aug 04, 2026
    • The domain tokhaiyte.vn was recently registered on April 4, 2024, by an individual named Lê Thanh Thủ, a suspicious sign commonly seen in fraudulent or copyright-infringing websites.
    • The website offers a series of copyrighted PDF books for free download, including many popular titles from major publishers in Vietnam, indicating a high likelihood that it is a source for distributing infringing content.
  • https://gcmmo.net/marketplace

    https://gcmmo.net/marketplace

    Risk score9/10Aug 04, 2026
    • The website sells digital accounts such as Facebook, TikTok, Google Ads, Gmail, Netflix, Gemini Pro, YouTube Premium at unusually low prices, which is a typical sign of trading in stolen accounts or violating terms of service.
    • The product 'Advertising Account Rental' clearly advertises avoiding VAT and incurring no card fees, indicating an attempt to circumvent the law and potentially involving money laundering or advertising fraud.
  • https://top68vn.live

    https://top68vn.live

    Risk score9/10Aug 04, 2026
    • The domain top68vn.live was registered recently on June 30, 2026, indicating it is a very new domain, often used by scam websites to avoid detection.
    • The domain uses the .live extension, an extension commonly used for websites with unreliable content or short-term operations.
  • https://hotrovieclamonline.com/login

    https://hotrovieclamonline.com/login

    Risk score9/10Aug 04, 2026
    • The domain hotrovieclamonline.com was recently registered on June 20, 2026, indicating it is a relatively new domain, often used by scammers for short-term campaigns.
    • The domain registration information is hidden through Domain Protection Services, a common sign of fraudulent websites aiming to conceal the true owner's identity.
  • https://naplau.com

    https://naplau.com

    Risk score9/10Aug 04, 2026
    • The website with the domain name naplau.com was registered by individual Doan Ngoc Huong on September 1, 2021. This is a personal website with no clear organizational information.
    • The website introduces itself as an illegal game top-up portal with automatic payment, providing top-up services for popular games such as Free Fire, Arena of Valor, PUBG Mobile, League of Legends: Wild Rift, and other games.
  • https://unlockffbeta.com

    https://unlockffbeta.com

    Risk score9/10Aug 04, 2026
    • This website requires users to verify their Astutech account by providing an Account ID or logging in via Discord, which is a typical sign of a scam aimed at stealing login credentials.
    • The domain unlockffbeta.com was recently registered on May 31, 2025, indicating that this is a newly created website, often used for short-term fraudulent activities.
  • https://tgbaoostore.vercel.app

    https://tgbaoostore.vercel.app

    Risk score9/10Aug 04, 2026
    • The website sells game hacking tools such as Script Kitten Panel, Aurora Panel, Kitten UID Bypass, and Minecraft Client Hack, which are products that violate the copyrights and terms of service of game developers.
    • The website offers Robux for sale at unusually low prices, a typical sign of scam sites or those using illegal Robux sources.
  • https://tailkhoangiare.com

    https://tailkhoangiare.com

    Risk score9/10Aug 04, 2026
    • The website sells cheap licensed accounts for many popular services such as YouTube Premium, Netflix, Spotify, ChatGPT, Canva Pro, CapCut Pro, Google One, and Microsoft Office 365 with deep discounts ranging from 18% to 65%, which is a typical sign of illegal account sales or unauthorized sharing.
    • The website offers Google Maps review boosting services, a violation of Google's policies and potentially involving online fraudulent activities.
  • https://ytmodz.com/vi

    https://ytmodz.com/vi

    Risk score9/10Aug 04, 2026
    • The website distributes modified (mod) APK files of YouTube, including YouTube Premium MOD, YouTube Vanced, and YouTube ReVanced, which are applications that violate Google's copyright and terms of service.
    • The website instructs users to download and install APK files from unknown sources, and requires enabling the 'Unknown Sources' option on Android devices, which significantly increases the risk of malware infection.
  • http://upd-latest.github.io/update

    http://upd-latest.github.io/update

    Risk score9/10Aug 04, 2026
    • The page is hosted on GitHub Pages (github.io), a legitimate platform, but the subdomain 'upd-latest' is suspicious and resembles patterns commonly used in phishing or malware distribution campaigns.
    • The page presents a minimal interface with a 'Downloading...' message and prompts the user to select an operating system (Windows or macOS), which is a classic social engineering tactic to deliver platform-specific malware payloads.

Miễn trừ trách nhiệm: Chúng tôi không đảm bảo kết quả chính xác và không chịu trách nhiệm cho bất cứ điều gì.