# PhishDestroy threat dossier — thenexusmarket.com ================================================================ Fetched: 2026-07-31 09:52:45 UTC Canonical: https://phishdestroy.io/domain/thenexusmarket.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 77/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 82.29.128.77 (US, New York) ASN: AS142036 Hosteons Pte. Ltd. Hosting org: Hosteons Pte. Ltd Registrar: Internet Domain Service BS Corp Nameservers: ["dns1.icedns.is", "dns2.icedns.is"] Page title: Nexus Market — Secure Darknet Marketplace & Database (2026) HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-15 Status: INVALID chain Fingerprint: 29d84719f08f3747ab0620745b41592b83a2ec6880dbc597b6e2c59ddd6541de Subject Alternative Names (related infrastructure — often same operator): - access.thenexusmarket.com - official.thenexusmarket.com - www.thenexusmarket.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 17:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 08:20:22 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 17:24:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] thenexusmarket.com Fake Credential Harvesting Alert The domain thenexusmarket.com is currently active and has been registered through Internet Domain Service BS Corp. DNS resolution is delegated to dns1.icedns.is and dns2.icedns.is, and HTTP requests receive a 301 permanent redirect response, indicating that the site is intentionally forwarding traffic, a common tactic for credential‑harvesting pages. VirusTotal analysis shows that six out of ninety‑one security vendors have flagged the domain, providing modest but notable detection coverage. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, confirming that at least one commercial feed considers it malicious. No public page title, SSL certificate details, IP address, or hosting provider information are presently available, and the specific brand or service being impersonated has not been disclosed in the intelligence set. Consequently, analysts cannot describe the exact visual or functional characteristics of the site, nor can they attribute it to a known phishing kit. The absence of these details creates uncertainty about the exact phishing scenario, but the observed infrastructure signals purposeful malicious activity. Defenders should add thenexusmarket.com to domain‑based blocklists, enforce DNS sinkholing for the associated nameservers, and monitor for any traffic patterns that reference the 301 redirect target. Continuous re‑scanning with VirusTotal and other sandbox environments is advised to capture any evolving payloads or credential‑capture mechanisms that may emerge as the campaign progresses. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 29d84719f08f3747ab0620745b41592b83a2ec6880dbc597b6e2c59ddd6541de ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/thenexusmarket.com/ JSON API: https://api.destroy.tools/v1/check?domain=thenexusmarket.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,255 domains (84,241 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io