whitelist-nexo[.]io
“Crypto Loan with Nexo | Get Funds And Keep Your Crypto”
whitelist-nexo.io — Accesible · acceso restringido (HTTP 403). Suplantación de marca: Ethereum; Tipo de estafa: Crypto Drainer. Resumen de las pruebas: VirusTotal 18/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); CF Radar malicious; PhishDestroy score 95/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, whitelist-nexo.io, poses a direct threat to cryptocurrency users by impersonating Ethereum-branded financial services. The site displays a fraudulent page titled 'Crypto Loan with Nexo | Get Funds And Keep Your Crypto,' designed to deceive visitors into entering sensitive credentials or transferring digital assets under false pretenses. Analysis indicates the domain is structured to exploit trust in established crypto lending platforms, potentially leading to unauthorized access to wallets or financial loss for victims who interact with its interface. Infrastructure analysis reveals multiple high-confidence indicators of malicious intent. The domain was registered on December 22, 2025, through NiceNIC International Group Co., Limited, a registrar frequently associated with suspicious registrations. It resolves to IP address 104.21.49.163, hosted on Cloudflare's network (AS13335), which is commonly used to obscure origin infrastructure. Security vendor assessments on VirusTotal show 18 out of 95 engines flagging the domain as malicious, while it appears on two independent security blocklists. The SSL certificate, issued by Google Trust Services (WE1), provides HTTPS encryption but does not validate legitimacy. Users who have visited whitelist-nexo.io should take immediate action to mitigate potential compromise. First, disconnect any active sessions and revoke permissions for connected wallet applications. Monitor all linked accounts for unauthorized transactions, particularly those involving Ethereum or ERC-20 tokens. If credentials were entered, reset passwords for all associated services and enable multi-factor authentication where available. Report the incident to relevant financial platforms and consider submitting the domain to additional threat intelligence feeds to support community defense efforts. The domain remains active as of this report, and users should avoid all interaction until further notice.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Latest Classified Outcome 2026-08-16 02:49:40 UTC
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of whitelist-nexo.io · checked Mar 1, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.