Analysis dated July 30, 2026 classifies rbxnexus.cc as a high‑risk generic phishing infrastructure. The domain was registered on July 10, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IP address 51.75.159.217. Authoritative name servers are carmelo.ns.cloudflare.com and mimi.ns.cloudflare.com, indicating use of Cloudflare's DNS service.
The domain appears on a single security blocklist and is actively blocked by PhishDestroy, confirming that defensive feeds are already flagging it. VirusTotal scans show that 4 of 91 security vendors have flagged the domain, providing independent corroboration of malicious intent. No additional public indicators such as page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts are presently available, leaving the content of the landing page uncharacterized.
Given the recent creation date, the use of reputable DNS hosting, and the early detection by multiple vendors, the infrastructure is likely being leveraged for credential harvesting or similar phishing campaigns. Defenders should add rbxnexus.cc to network and endpoint blocklists, monitor DNS queries for the associated Cloudflare name servers, and consider sinkholing the IP address 51.75.159.217 where feasible. Continuous re‑evaluation is advised as further telemetry, such as URL paths or payload samples, becomes available.