Analysis of nexus-info.digital indicates active phishing infrastructure with high-risk characteristics. The domain was registered on July 25, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious registrations. Infrastructure analysis reveals Cloudflare nameservers (adel.ns.cloudflare.com, javon.ns.cloudflare.com) and resolution to IP address 104.21.2.230, a shared hosting environment commonly exploited for phishing campaigns. As of July 28, 2026, the domain remains active and appears on one security blocklist, with PhishDestroy specifically blocking it.
VirusTotal scans show two of 91 security vendors flagging the domain, though the exact nature of the detected threat remains unconfirmed. No brand target or phishing kit has been identified in available data, and the page content has not been analyzed. The recent registration date, combined with Cloudflare hosting and minimal detection coverage, suggests an attempt to evade initial security scrutiny.
Defenders should treat this domain as malicious and implement blocking at the DNS or network level. Further investigation into associated IP ranges and registrar patterns may reveal additional linked infrastructure. Given the domain's active status and phishing classification, monitoring for new detections or shifts in hosting is recommended.