The domain top-nexus.cfd is currently listed as an active generic phishing site. Registration data shows it was created on July 25, 2026 by NICENIC INTERNATIONAL GROUP CO., LIMITED, and it resolves to the Cloudflare edge address 104.21.29.156. The authoritative nameservers are adel.ns.cloudflare.com and javon.ns.cloudflare.com, indicating the infrastructure is fully hosted behind Cloudflare’s CDN and DDoS protection services.
The domain has been added to the PhishDestroy blocklist and appears on one additional security blocklist, confirming that at least two external sources consider it malicious. VirusTotal analysis reports that 1 of 91 security vendors flagged the domain, which, despite the low detection count, aligns with the high‑risk classification due to its recent creation and active status. No further intelligence such as page title, SSL certificate details, or Safe Browsing verdicts is available, leaving the exact phishing content and target brand undocumented.
Defenders should treat the domain as hostile: immediately block the IP address 104.21.29.156 and the FQDN top-nexus.cfd at network perimeter devices, DNS resolvers, and proxy filters; monitor outbound traffic for connections to Cloudflare edge nodes that could be leveraged for credential harvesting; and consider submitting the URL to sandbox environments for deeper behavioral analysis. Continuous re‑evaluation is advised, as the site’s content, SSL configuration, or additional detections may evolve rapidly given its recent registration.