Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 3. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

nexus-access[.]shop

“Nexus Market Access 2026 — Verified Onion + Step-by-Step”

Threat verdict High 69/100 evidence score
Availability Last known active Latest stored reachability observation
VirusTotal detections: 3/91 Brand impersonation: Across Last known active
Aug 1, 2026 Across CDN

Evidence Summary

HIGH
Evidence score
69/100

Analysis of the domain nexus-access.shop, observed on the report date of August 01, 2026, indicates that the site is actively being used for a generic phishing campaign. The domain resolves to the IPv4 address 188.114.96.3 and is hosted behind the Cloudflare nameservers marge.ns.cloudflare.com and west.ns.cloudflare.com. Reputation data shows the domain appears on a single security blocklist and is currently blocked by the PhishDestroy service, confirming that at least one external mitigation platform has taken action against it.

VirusTotal records reveal that the domain was scanned by 91 independent antivirus and URL‑reputation vendors; none of the scanners reported a detection at the time of analysis, a fact that should not be interpreted as evidence of safety but rather as an indication that the malicious payload may be evasive or not yet identified by the participating engines. No additional intelligence such as registrar details, SSL certificate metadata, HTTP response codes, or page‑title information is available in the current dataset, leaving those aspects of the infrastructure unverified. The lack of further public signals means that the full scope of the phishing operation—including the targeted brand, specific credential‑harvesting pages, or any associated command‑and‑control infrastructure—remains unknown.

Defenders are advised to proactively block the domain and its resolved IP address at network perimeters, incorporate the domain into internal threat‑intelligence feeds, and monitor for any future detections or blocklist additions. Continuous re‑evaluation of the domain through periodic VirusTotal rescans and observation of emerging blocklist entries is recommended to capture any changes in its threat profile.

VirusTotal
VirusTotal
3 det.
TLS Certificate
Let's Encrypt
Observed status
Last known active HTTP 200
PhishDestroy
DestroyList
Listed

Data Coverage

VirusTotal 3 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks not checked TLS valid certificate, 50d WHOIS not parsed Screenshot 2 captures · 2 sources Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
13/15

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 11, 2026

10 monitored external feeds No match

Detection timeline

  1. First recorded

    First stored value: Reachable

Stored Capture

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN cloudflare · AS13335 CLOUDFLARENET - Cloudflare, Inc., US
IP Context Cloudflare shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
IP Address 188.114.96.3 CDN
GeoUS San Francisco, US
NetworkAS13335 · Cloudflare, Inc.
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
HTTP Status200
Technical detailsDNS, TLS names and timestamps
First DetectedAug 1, 2026
DOM Analysisanalyzed Aug 1, 2026DOM analysis score 63/1003 brand signals
Submitted URLhttps://nexus-access.shop/
Nameserversmarge.ns.cloudflare.comwest.ns.cloudflare.com
Favicon Hash
Page Title
Nexus Market Access 2026 — Verified Onion + Step-by-Step
Impersonates
Across Reddit Telegram
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt · valid for 50 days

Technologies

3 high-confidence technologies identified

Cloudflare Browser Insights Cloudflare HTTP/3
Cloudflare Radar
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

3 / 91 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 2 detections
Forcepoint ThreatSeeker
Gridinsoft
SOCRadar

Archived Evidence

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of nexus-access.shop · checked Aug 1, 2026

100
Good
Performance
FCP
0.81s
First Contentful Paint
LCP
0.87s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.28s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Stored Capture Evidence1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: https://nexus-access.shop/
Nexus Market Access 2026 — Verified Onion + Step-by-Step
How to access Nexus Market in 2026: three live onion mirrors, verified signature and the step-by-step login flow that keeps your account out of phishing clones.
Response
HTTP 200
HTML body
13.5 KB
Compressed
4.5 KB
Links
13 internal · 0 external
Detected technologies
cloudflare
Selected response headers
Content-Type: text/html; charset=utf-8
Server: cloudflare
CF-Cache-Status: DYNAMIC
Content-Encoding: gzip
Security headers present
X-Content-Type-OptionsReferrer-Policy
HSTS: not observed DNSSEC: not observed WAF / firewall: observed Cloaking flag: not observed
Favicon fingerprint: 61802ef3a8c34c20d4c7bab4696dc962f9163c24638a97d3f5f0db7f4247af58
Open Graph title: Nexus Market Access 2026 — Verified Onion + Step-by-Step
Open Graph description: How to access Nexus Market in 2026: three live onion mirrors, verified signature and the step-by-step login flow that keeps your account out of phishing clones.
Twitter card: summary
All stored response-header names (14)
DateContent-TypeTransfer-EncodingConnectionX-Content-Type-OptionsReferrer-PolicyReport-ToServercf-cache-statusNelServer-TimingContent-EncodingCF-RAYalt-svc
Site Configuration Analysis
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap 5 pages · HTTP 200

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/nexus-access.shop"
  title="PhishDestroy threat report for nexus-access.shop"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>