# PhishDestroy threat dossier — nexus-url.cfd ================================================================ Fetched: 2026-07-30 16:11:20 UTC Canonical: https://phishdestroy.io/domain/nexus-url.cfd/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Fortinet AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: adel.ns.cloudflare.com, javon.ns.cloudflare.com Registered: 2026-07-25 Expires: 2027-07-25 Page title: Nexus Market • verified mirror routing and uptime tracking ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-23 Status: INVALID chain Fingerprint: 5358c5b28370f227ef37c050ba4f1ee758ed099f5a72d9c1e2bcc780d24b25f0 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 19:49:26 UTC (by PhishDestroy tracker) First reported: 2026-07-28 17:59:48 UTC (abuse notice filed) Last verified: 2026-07-30 16:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9d8-74b6-741c-aa0c-e1d818578717/ URLQuery: https://urlquery.net/report/1be5acba-911a-455a-87ed-84fc40fda10a Wayback Machine: https://web.archive.org/web/*/nexus-url.cfd crt.sh CT logs: https://crt.sh/?q=%25.nexus-url.cfd Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=nexus-url.cfd AlienVault OTX: https://otx.alienvault.com/indicator/domain/nexus-url.cfd URLhaus: https://urlhaus.abuse.ch/host/nexus-url.cfd/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 20:58:17 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] nexus-url.cfd: Confirmed Phishing Site Analysis of nexus-url.cfd indicates that the domain is actively being used for a generic phishing campaign. The domain was registered on July 25, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolved to the IP address 188.114.97.3, which is owned by CloudFlare, Inc. and geolocated to Canada. The hosting arrangement uses CloudFlare nameservers adel.ns.cloudflare.com and javon.ns.cloudflare.com, a common pattern for fast‑flux or proxy‑based phishing infrastructures. The site is protected by an SSL certificate issued by Google Trust Services, a legitimate certificate authority often leveraged by malicious actors to increase user trust. Security telemetry shows that the domain is blocked by PhishDestroy and appears on one external security blocklist, demonstrating that at least one threat‑intelligence feed has flagged it. VirusTotal reports a single positive detection out of 91 scanned security vendors, confirming that at least one vendor has identified malicious behavior. No additional public analysis, such as page title or content inspection, is currently available, leaving the precise phishing lure and targeted brand unspecified. Defenders should treat the domain as hostile: network firewalls and DNS filtering should be configured to block nexus-url.cfd and its resolved IP, logging of any outbound connections to the domain should be enabled, and the domain should be added to internal blocklists. Continuous monitoring of related CloudFlare‑hosted IPs and the registrar’s recent registrations is advised to detect potential sibling domains that may share the same infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-BB126B Favicon MD5: a10167f5b34d763cda797edf9fda2292 TLS cert SHA-256: 5358c5b28370f227ef37c050ba4f1ee758ed099f5a72d9c1e2bcc780d24b25f0 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/nexus-url.cfd/ JSON API: https://api.destroy.tools/v1/check?domain=nexus-url.cfd Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,932 domains (83,630 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io