best-nexus[.]sbs
“Nexus Market | Official Onion Links & Verified Mirrors 2026”
Evidence Summary
Analysis of the domain best-nexus.sbs, observed on 3 August 2026, indicates that the site is being used for a generic phishing campaign. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy service, confirming that it is recognized by at least one phishing mitigation platform. VirusTotal records show that the domain was submitted for scanning and evaluated by 91 antivirus and URL‑reputation vendors; none of the vendors generated a detection at the time of the scan. While the absence of detections does not constitute evidence of benign behavior, it does suggest that the payload or hosting infrastructure has not yet been fingerprinted by automated scanners.
No further technical details such as registrar information, hosting IP address, ASN, TLS certificate data, or HTTP response codes are presently available in the intelligence feed. Consequently, the precise infrastructure supporting best‑nexus.sbs cannot be profiled at this stage. Defenders should continue to block the domain at network perimeter devices and incorporate it into URL filtering rules, especially within environments that enforce strict outbound web controls.
Monitoring for any future appearance on additional blocklists or for changes in VirusTotal detection counts is advisable, as an increase in vendor detections would indicate that the site’s malicious content has been more widely identified. Organizations should also consider notifying users of the potential phishing risk, particularly if the domain is observed in phishing email headers or as a hyperlink in suspicious messages. In summary, the evidence currently available classifies best‑nexus.sbs as an active generic phishing site, with limited but concrete indicators of malicious intent and no confirmed safe status.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
SHORTDOT ZONE · PUBLIC EVIDENCE
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
4 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of best-nexus.sbs · checked Aug 3, 2026
Site Configuration Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive