whitelist[.]blockchain-nexo[.]io
“blockchain-nexo.io | 522: Connection timed out”
whitelist.blockchain-nexo.io — Serverfehler (HTTP 502). Markenidentität: Blockchain.com; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 17/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Certego); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: NiceNIC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of the domain whitelist.blockchain-nexo.io confirms its classification as an airdrop crypto scam targeting Blockchain.com users. The domain, registered on December 31, 2025, through NiceNIC International Group Co., Limited, currently resolves to 188.114.96.3, a Cloudflare IP address (AS13335) located in the US. Infrastructure analysis reveals Cloudflare nameservers (haley.ns.cloudflare.com and tanner.ns.cloudflare.com), though no SSL certificate is present. The domain is offline as of the report date, returning a 522 connection timeout with the page title 'blockchain-nexo.io | 522: Connection timed out.' Detection data indicates elevated risk: 17 of 93 security vendors on VirusTotal flag the domain, and it appears on one security blocklist (PhishDestroy).
Gridinsoft assigns a trust score of 0/100. The scam type is explicitly identified as an airdrop scam, and the domain impersonates Blockchain.com, a known cryptocurrency platform. While the exact content of the site remains unanalyzed due to its offline status, the combination of brand impersonation, airdrop scam classification, and detection by multiple vendors confirms malicious intent. Defenders should treat this domain as confirmed malicious and prioritize blocking it at DNS and network levels.
The use of Cloudflare infrastructure is consistent with threat actors leveraging CDN services to obscure hosting origins. Given the domain's creation date and offline status, it may have been part of a short-lived campaign or taken down following detection. No additional phishing kit artifacts or payloads are currently linked to this domain. Further monitoring is recommended to identify potential re-emergence under alternate domains or IPs.
Erkenntnisse zur Netzwerksicherheit Registrar context
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Latest Classified Outcome 2026-08-15 12:53:43 UTC
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt