Analysis of link.nexus1darknet.com indicates that the domain is currently active and associated with a generic phishing campaign. The domain was registered on October 01, 2025 through the registrar TUCOWS.COM, CO, and is served by Cloudflare name servers demi.ns.cloudflare.com and lars.ns.cloudflare.com. DNS resolution points to the IPv4 address 188.114.96.3, which is the sole hosting endpoint observed for this infrastructure.
The domain appears on a single public blocklist and has been explicitly blocked by the PhishDestroy mitigation service, demonstrating that at least one security vendor has identified the domain as malicious. VirusTotal records show that the domain was scanned by 91 antivirus and URL‑reputation engines, none of which raised a detection; however, the absence of a detection does not constitute confirmation of safety. The limited visibility—no publicly disclosed SSL certificate details, HTTP response codes, or page title—means that the full content and behavior of the site remain unverified.
Defenders should treat the domain as hostile, enforce network‑level blocking of both the domain and its resolving IP, and monitor for any new indicators that may emerge from additional scans or threat‑intel feeds. Given the recent creation date and active status, continued observation is warranted to detect any evolution of the phishing infrastructure.