Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
drughub[.]nexus
“DrugHub - Veilige XMR Darknet Marktplaats”
Riepilogo delle prove
The domain drughub.nexus presents an elevated risk as a generic phishing threat, indicated by its use of misleading elements to deceive users. The domain, now offline, was originally designed to impersonate a secure marketplace, as suggested by its page title 'DrugHub - Veilige XMR Darknet Marktplaats', which targets users seeking anonymity for potentially illicit transactions.
The specific data points collected reveal significant findings: the domain was created on January 13, 2026, and was resolving to the IP address 172.67.149.30. It employed technologies such as Cloudflare Browser Insights and HTTP/3, which are commonly used to mask the actual server location and enhance the site's perceived legitimacy. Despite its offline status, drughub.nexus was flagged by 5 out of 95 security vendors on VirusTotal and appeared on one security blocklist, specifically noted by PhishDestroy. This domain's SSL certificate was issued by Google Trust Services, adding another layer of deceit. Further, it was registered through Spaceship, Inc., and documented in four threat intelligence pulses on AlienVault OTX, indicating a broader awareness of its malicious potential.
To mitigate risks from similar phishing threats, users are advised to remain vigilant about domains that mimic legitimate services with minor variations. Utilizing multi-factor authentication, regularly updating security software, and educating users about common phishing tactics can reduce exposure to such threats. Network administrators should implement domain filtering to block known malicious domains, such as those flagged by threat intelligence sources. Additionally, monitoring for traffic to suspicious IPs like 172.67.149.30 can assist in identifying potential attacks early.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260528-60598A- Titolo della pagina acquisita
- DrugHub - Veilige XMR Darknet Marktplaats
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Acceptable Use Policy (AUP) - Section 3.1: The domain drughub.nexus is engaged in illegal activities, specifically phishing, which is strictly prohibited under your AUP.
Terms of Service (TOS) - Section 5.2: The use of this domain for deceptive practices constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such actions.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030: This law prohibits unauthorized access to computer systems and the use of such access to commit fraud.
Wire Fraud Statute - 18 U.S.C. § 1343: This statute criminalizes schemes to defraud individuals or entities through electronic communications, including phishing.
Regulatory Note: Failure to take immediate action against drughub.nexus may result in liability for facilitating illegal activities, potentially leading to regulatory scrutiny and enforcement actions against your organization.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
VirusTotal
0 → 5
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of drughub.nexus · checked Jun 26, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo