# PhishDestroy threat dossier — nexus77.store ================================================================ Fetched: 2026-05-25 02:52:37 UTC Canonical: https://phishdestroy.io/domain/nexus77.store/ ## VERDICT ---------------------------------------------------------------- STATUS STALE — last probed 41 days ago, treat as ACTIVE until re-verified Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation (american express) Targeted brand: american express (and: apple, google, mastercard, paypal, shopify) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/95 security vendors flagged this domain Flagging vendors: ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Fortinet, G-Data, Google Safebrowsing, Gridinsoft, Lionic, Seclookup, SOCRadar Public blocklists: listed on 2 independent blocklists Google Safe Browsing: FLAGGED Victim re-reports (public form): 1 ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 23.227.38.65 (CA, Ottawa) ASN: ASAS13335 CLOUDFLARENET, US Hosting org: AS13335 Cloudflare, Inc. Registrar: Squarespace Domains LLC Nameservers: ns-cloud-e1.googledomains.com, ns-cloud-e2.googledomains.com, ns-cloud-e3.googledomains.com, ns-cloud-e4.googledomains.com Registered: 2025-11-20 Page title: Nexus TouchScreen Bluetooth Earbuds – Noise Cancelling Smart Display ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-04-24 Status: INVALID chain Fingerprint: 5063b468c0960a5cec6e792cfeaa950a11736b2af4335b852844604c2ce7a10d ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-11-20 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-25 02:39:27 UTC (by PhishDestroy tracker) First reported: 2025-11-22 13:02:18 UTC (abuse notice filed) Last verified: 2026-04-13 07:52:12 UTC (STALE — 41 days ago, re-verify) Flagged dead: 2026-03-15 06:12:30 UTC (NOT RE-VERIFIED IN 41 DAYS — treat as unconfirmed) Current status: UNCONFIRMED (our live-probe is 41 days stale) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019aaba7-b629-726f-9939-ea72b649ac20/ Wayback Machine: https://web.archive.org/web/*/nexus77.store crt.sh CT logs: https://crt.sh/?q=%25.nexus77.store Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=nexus77.store AlienVault OTX: https://otx.alienvault.com/indicator/domain/nexus77.store URLhaus: https://urlhaus.abuse.ch/host/nexus77.store/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-03-19 01:35:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies nexus77.store as a high-risk domain engaged in brand impersonation targeting American Express. The domain was registered on November 20, 2025, and falsely presented itself with a page titled "Nexus TouchScreen Bluetooth Earbuds – Noise Cancelling Smart Display," a misleading lure unrelated to the brand it impersonates. This tactic aims to deceive users into trusting the site under the guise of a legitimate financial institution. Technical analysis reveals that nexus77.store resolved to the IP address 23.227.38.65 and was registered via Squarespace Domains LLC. Google Safe Browsing has flagged this domain for social engineering, highlighting its malicious intent. VirusTotal scans show that 13 out of 95 security vendors detected suspicious activity linked to this domain. Additionally, it appears on two separate security blocklists and holds a Gridinsoft trust score of 0 out of 100, further confirming its high-risk status. Currently, nexus77.store is offline, reflecting effective mitigation efforts or domain takedown actions. Despite its offline status, users should remain vigilant as similar brand impersonation campaigns continue to proliferate. PhishDestroy recommends blocking this domain and monitoring for any resurgence or related threats leveraging the American Express brand to safeguard against potential phishing attacks. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon SHA-256: ec909faa2d768b966183aea74896094a66593995b18cdb7dd6aafeccd225bf66 TLS cert SHA-256: 5063b468c0960a5cec6e792cfeaa950a11736b2af4335b852844604c2ce7a10d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/nexus77.store/ JSON API: https://api.destroy.tools/v1/check?domain=nexus77.store Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 152,979 domains (39,789 alive under monitoring, 112,805 confirmed takedowns/dead). Site: https://phishdestroy.io