Credential theft and impersonation domains
Targets login theft, credential capture, impersonation, fake account portals, and other domains used to trick users into handing over access or payment details.
Pull enforcement-ready domain snapshots built for DNS filtering, firewall policy, and security pipelines that need domains they can actually act on, not a dump of every internal signal.
Have questions about our API, pricing, or need a custom solution? Fill out the form below.
The feed is organized around enforcement outcomes, not internal taxonomy. Instead of handing off dozens of narrow labels, we package related detections into stable streams that map directly to blocklists, resolver policy, and analyst review queues.
Targets login theft, credential capture, impersonation, fake account portals, and other domains used to trick users into handing over access or payment details.
Focused on payload hosting, droppers, fake software downloads, malicious installers, and other domains used to deliver malware or unwanted binaries.
Built for fraud-oriented blocking. It combines the major scam families into one stream so teams can stop social-engineering and payment-extraction funnels without maintaining separate mappings for each scam subtype.
Designed for destinations that often need softer enforcement, user warning, or separate review rather than the same hard-block policy used for phishing and malware. Typical examples include suspicious shops, suspicious dating, browser spam, and unwanted-app destinations.
Delivery is optimized for scheduled ingestion, not analyst browsing: stable columns, full snapshots, predictable refresh cadence, and enough context to support both automated action and human review without forcing a second enrichment system.
Minimal enough for DNS and firewall pipelines, while still preserving the context analysts need when a blocked domain is escalated or reviewed.
domain,category,risk_score,report_url
example-phish.com,Phishing,96,https://gridinsoft.com/online-virus-scanner/url/example-phish-com
example-scam.net,Investment Scam,91,https://gridinsoft.com/online-virus-scanner/url/example-scam-net
example-shop.org,Suspicious Shop,84,https://gridinsoft.com/online-virus-scanner/url/example-shop-org
The goal is to make evaluation operational quickly: agree the policy target, align the scope, measure block yield and review overhead, and then decide whether the feed earns a production slot.
We map your environment, enforcement point, and which threat streams should land in hard block, softer policy, or analyst review.
We align the feed scope, delivery format, and the access or legal framework needed for the PoC.
Your team ingests hourly snapshots and measures block yield, quality, review overhead, and operational fit inside the actual policy stack.
If the feed performs, we lock in production scope, access model, and the commercial framework.
Tell us where the feed would sit in your stack, which policy decisions it is meant to support, and what you want to measure during evaluation. We will help scope the right access path.
Have questions about our API, pricing, or need a custom solution? Fill out the form below.
You have reached the limit of your current plan. Please subscribe to the Pro plan to continue using the service.
Designed for small to medium enterprises requiring regular API access with standard support.
Suited for businesses needing high-volume access and additional API capabilities, along with priority support.
For large organizations requiring full-scale API integration with the highest level of support and customization.
If you would like to discuss custom arrangements, please do not hesitate to contact us. We are always ready to help you find the perfect solution that meets your needs.
Have questions about our API, pricing, or need a custom solution? Fill out the form below.