Analysis of zone.nexus-tor-link.net as of August 1, 2026, indicates an active domain under investigation for generic phishing activity. The domain was registered on June 2, 2026, through Dynadot Inc and currently resolves to IP address 104.21.39.111, hosted on Cloudflare infrastructure as evidenced by its nameservers (aurora.ns.cloudflare.com and fonzie.ns.cloudflare.com). At present, the domain appears on one security blocklist, specifically PhishDestroy, though it is not flagged by any of the 91 vendors in the most recent VirusTotal scan. The absence of detections in VirusTotal does not confirm safety, as phishing domains often evade initial scans through evasion techniques or delayed malicious activation.
Infrastructure analysis reveals Cloudflare hosting, which is frequently leveraged by threat actors to obscure origin servers and enhance resilience against takedowns. The domain's registration age—just two months old—aligns with common phishing domain lifecycle patterns, where rapid deployment and short-lived use are typical. Defenders should note that no specific brand impersonation, phishing kit, or page content has been confirmed in available data; thus, the exact nature of the phishing scheme remains unclassified.
Recommended actions include monitoring network traffic for connections to 104.21.39.111 or the domain itself, particularly in environments where Tor or anonymized traffic is permitted. Security teams should review PhishDestroy’s blocklist entry for additional context and consider implementing DNS-based blocking for zone.nexus-tor-link.net pending further analysis. Given the domain’s active status and Cloudflare hosting, defenders should prioritize proactive detection over reliance on vendor scans, which may lag behind real-time threats.