Live phishing gallery

Live Phishing Tracker: 374 UltaHost Domains Still Active

A categorized snapshot of phishing domains registered through UltaHost as of July 19, 2026. 374 of 871 flagged domains remain live — a 33.7% alive rate. 58% of formally reported domains still serve victims despite abuse reports being filed.

Last verified: May 17, 2026 against PhishDestroy registrar stats. We re-check monthly. For the full current list, see PhishDestroy's live UltaHost domain page.

871
Flagged domains
374
Still LIVE (33.7%)
58%
Active after report
98.4%
VirusTotal-confirmed

How to read this page: Each card shows a phishing domain registered through UltaHost. LIVE means the domain was reachable at last verification. VT is the VirusTotal threat score from 70+ antivirus engines. A score of 5+ is high confidence; 15+ is overwhelming consensus.

Bank Impersonation (LIVE)

webchasesavings.com
VT 12
bcvbk.com
VT 9
virtabanks.net
VT 8
fnbux.com
LiveVT 7
versatilebk.com
LiveVT 7
equityccu.com
VT 6
ubsnovus.com
VT 19
firstmidwestsbank.com
VT 16

Web3 / Crypto Wallet Phishing (Drainer Sites)

metamaskusdt.com
VT 16
trezor.io-suite.org
VT 16
tether-claim.com
VT 11
trustwalletconnect.net
VT 10
vortewallet.com
LiveVT 8
shieldweb3ledge.com
VT 7
authsecureuser.net
VT 6
ledger-protect.xyz
walletdrainer.site
VT 15

Pig Butchering / Investment Fraud (LIVE)

valoreal-capital.com
VT 9
hudsondigitalcorporation.com
VT 8
wealthtech-global.com
LiveVT 7
eurobit-international.com
LiveVT 7
bitcoretrade.com
LiveVT 6
tenderlytradepro.com
VT 8
granddominiontrust.org

Airdrop Scams (Fake Crypto Giveaways, LIVE)

monadairdrops.xyz
zentryairdrop.xyz
zkverifyairdrop.xyz
d3airdrop.xyz
archnetworkairdrop.xyz
billionsairdrop.xyz
raylsairdrop.xyz

Token Presale Scams (Fake ICO, LIVE)

kalshipresale.xyz
edgenpresale.xyz
rialotoken.xyz

Government Impersonation

jandhanyojna.org
maxdeptgov.com
masdeptgov.com

Trading Platform Fraud (LIVE)

elontrade-firm.com
Live
foxminingwayoption.com
Live
bara-ai.com
Live
24robinhoodtradingoption.com

Wallet-drainer malware families detected on UltaHost domains

Counts are system-wide PhishDestroy detections. Each represents an automated tool that empties a victim's crypto wallet in one transaction:

Angel Drainer (4,379)Solana Drainer (2,121)Wallet Connect Abuse (1,668)Ice Phishing (42)Inferno Drainer (41)MS Drainer (1+)Pink Drainer (1+)Venom Drainer (1+)

Brands most heavily impersonated

At least 18 major brand names appear in phishing domains registered through UltaHost:

BaseLedgerCoinbaseAcrossSolanaKrakenGoogleEthereumOKXMetaMaskTrezorAaveBinanceSushiSwapFacebookTrust WalletBitcoinWalletConnect

The domain that says the quiet part out loud: walletdrainer.site — registered through UltaHost, with the literal crime in the domain name itself. It stayed live for months of formal abuse reports and finally went offline (NXDOMAIN) only by our July 19, 2026re-check. UltaHost's abuse-gatekeeping pattern (Gmail reporters dismissed, trademark required) meant a domain whose entire reason for existing was to drain wallets stayed operational because no one with appropriate legal credentials had reported it.

Verify these are still live yourself

Pick any domain above. Check its current status across these independent sources:

Important: do NOT visit these domains in your normal browser. They are live malware. Use a sandboxed environment (browser isolation service, dedicated VM, or just read the screenshots on PhishDestroy).