nexus-auth[.]de
Analyse phishing et sécurité de nexus-auth.de
“Nexus Authority”
nexus-auth.de — Dernier actif connu (HTTP 303). Résumé des preuves: VirusTotal 12/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 96/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
nexus-auth.de is currently observed as an active generic phishing infrastructure. The domain resolves to the IPv4 address 45.81.232.18 and returns an HTTP 303 status, indicating a redirection flow typical of credential‑harvesting sites. The TLS handshake is performed with a Let’s Encrypt R12 certificate, providing encryption but no indication of legitimate ownership.
The hosting environment is tied to the autonomous system AS44486, registered to synlinq.de, and the IP is geolocated in Germany. Name resolution is delegated to ns1.mc-host24.de and ns2.mc-host24.de, both of which are commonly associated with shared hosting services. Reputation scoring from Gridinsoft assigns a zero out of one hundred, reflecting an extremely low trust rating.
Reputation services have flagged the domain. PhishDestroy includes nexus‑auth.de on its blocklist, and the domain appears on one additional security blocklist. AlienVault OTX lists the domain in a single threat‑intelligence pulse. VirusTotal reports that seven out of ninety‑five scanning engines have raised detections, reinforcing the malicious classification.
The publicly available page title is “Nexus Authority,” but no further content analysis is available in the current data set. Consequently, the precise luring technique, targeted brand, or credential‑capture template remains unknown. Analysts should treat the domain as a phishing vector until additional forensic evidence confirms the exact payload.
Defenders are advised to block both the domain name and its resolving IP address at perimeter and DNS layers. Continuous monitoring for new host‑header variations or additional IPs is recommended, as the infrastructure may be expanded. Integrating the domain into internal threat‑intel feeds will aid in rapid detection and mitigation.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of nexus-auth.de · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif