Malicious websites today

31,994

Malicious websites this week

136,730

Malicious websites this month

1,727,303

Total malicious websites

21,552,177

TLD distribution

  • .com - 50.3%
  • .top - 17.1%
  • .xyz - 10.0%
  • .cc - 6.2%
  • .buzz - 3.4%
  • .shop - 3.3%
  • .net - 3.0%
  • .cn - 2.5%
  • .org - 2.3%
  • .info - 1.8%

Threat trend

20.0M20.5M21.0M21.6M
Threats
05/0911/0917/0922/0928/0904/10

Recent threats

  • https://enhancedconfiguration.app/ledger.com

    https://enhancedconfiguration.app/ledger.com

    Risk score10/10Oct 04, 2026
    • The domain enhancedconfiguration.app was registered very recently on August 7, 2026, which is a common indicator of malicious or phishing infrastructure.
    • The URL path /ledger.com is a classic subdomain impersonation technique, attempting to make the URL appear as if it belongs to the legitimate ledger.com domain.
  • https://capcutpro.org.in

    https://capcutpro.org.in

    Risk score10/10Oct 04, 2026
    • The domain capcutpro.org.in is a recently registered website, created on December 26, 2024, which is a common pattern for malicious sites that are quickly set up and abandoned.
    • The registrant is listed as White Wolves LLC, a generic entity often used to obscure the true ownership of suspicious websites.
  • https://depot--official.com

    https://depot--official.com

    Risk score9/10Oct 04, 2026
    • The domain depot--official.com was registered very recently on October 4, 2026, which is a common characteristic of short-lived fraudulent websites.
    • The domain name uses a double-hyphen pattern (depot--official), which is a known tactic used by scammers to impersonate legitimate brands and evade detection.
  • https://depot--online.com

    https://depot--online.com

    Risk score9/10Oct 04, 2026
    • The domain depot--online.com was registered very recently on October 4, 2026, which is an extremely short operational history and a common trait of fraudulent or short-lived scam websites.
    • The domain name uses a double hyphen (depot--online) rather than the legitimate single-hyphen format (depot-online) used by the well-known German home decor retailer DEPOT, indicating a likely typosquatting or impersonation attempt.
  • https://qr.bankers.vn

    https://qr.bankers.vn

    Risk score9/10Oct 04, 2026
    • The domain bankers.vn was registered in 2015 by an individual named Đỗ Thành Trung, which is not a recognized banking institution and raises concerns about legitimacy for a page impersonating VietinBank.
    • The URL uses a subdomain qr.bankers.vn, which is not an official VietinBank domain; legitimate VietinBank services would be hosted on vietinbank.vn.
  • https://breachforums.hn

    https://breachforums.hn

    Risk score10/10Oct 04, 2026
    • The page displays a seizure notice from multiple law enforcement agencies including the FBI, Department of Justice, French law enforcement (BL2C), and the Paris Prosecutor's Office (JUNALCO).
    • The domain breachforums.hn was registered on April 19, 2024, which is relatively recent and consistent with the timeline of the BreachForums takedown operation.
  • https://earntask.io

    https://earntask.io

    Risk score9/10Oct 04, 2026
    • The domain was registered very recently on November 24, 2025, which is a common characteristic of fraudulent or short-lived scam websites.
    • The site promises easy money for completing simple social media tasks such as posting comments, liking posts, and writing reviews, a classic structure used in task scams that often serve as fronts for money laundering or engagement manipulation.
  • https://picstores.shop.group-2.online

    https://picstores.shop.group-2.online

    Risk score9/10Oct 04, 2026
    • The domain group-2.online was registered very recently on February 20, 2024, which is a common characteristic of throwaway domains used for malicious campaigns.
    • The URL path picstores.shop.group-2.online uses a subdomain structure that mimics legitimate services, a tactic frequently used in phishing and malware distribution.
  • https://reddit-task-money.lovable.app

    https://reddit-task-money.lovable.app

    Risk score9/10Oct 04, 2026
    • The site is hosted on lovable.app, a platform that allows rapid deployment of web applications, which is frequently abused by scammers to quickly spin up fraudulent pages.
    • The domain 'reddit-task-money.lovable.app' is a subdomain designed to impersonate or closely associate with Reddit, a common social engineering tactic to appear legitimate.
  • https://redditearn.lovable.app

    https://redditearn.lovable.app

    Risk score9/10Oct 04, 2026
    • The page is hosted on lovable.app, a free website builder platform that is frequently abused by scammers to quickly create and deploy fraudulent landing pages without registering their own domain.
    • The site recruits users to perform paid posting and commenting tasks on Reddit, which is a classic structure of a 'paid-to-click' or content manipulation scam where victims are eventually asked to pay upfront fees or launder money.
  • https://taskreddit.com

    https://taskreddit.com

    Risk score9/10Oct 04, 2026
    • The site offers payment in cryptocurrency for posting opinions on Reddit, which is a common structure for astroturfing and influence-for-hire operations that compromise platform integrity.
    • The domain was registered very recently on July 31, 2026, which is only a couple of months old, a typical pattern for short-lived scam or illicit service operations.
  • https://datanodes.to/lls1w59qtdoq/train45_-_steamgg.net.zip

    https://datanodes.to/lls1w59qtdoq/train45_-_s...

    Risk score9/10Oct 03, 2026
    • The page is hosted on a file-sharing service that is being used to distribute a large 1.4 GB ZIP archive, which is a common vector for bundling malware with legitimate-looking content.
    • The file is named 'Train45 - SteamGG.NET.zip' and references 'steamgg.net', a domain that is not a recognized official Steam partner, suggesting the use of a brand impersonation tactic to lure users interested in gaming content.

Miễn trừ trách nhiệm: Chúng tôi không đảm bảo kết quả chính xác và không chịu trách nhiệm cho bất cứ điều gì.