This domain, m.nevexglobal.com, is flagged as a high-risk generic phishing threat as of the July 30, 2026 report date and remains actively resolving. The domain was created on April 30, 2017, and is registered through GoDaddy.com, LLC. It resolves to IP address 104.21.83.249 and uses Cloudflare nameservers (cleo.ns.cloudflare.com and dorthy.ns.cloudflare.com), which may provide content delivery network and DDoS protection, potentially obscuring the true origin server. VirusTotal analysis shows 1 out of 91 security vendors flagging this domain as malicious, and it appears on 1 security blocklist; it is specifically blocked by PhishDestroy.
No Safe Browsing, OTX, SSL, HTTP status, trust score, or page title data was provided in the known intelligence, so the exact content and impersonated brand remain unconfirmed. The single vendor detection and blocklist presence indicate a low but notable malicious signal, consistent with a domain that may be used sporadically or for targeted campaigns. Defenders should treat this domain as suspicious and investigate further by reviewing the live page content, checking for any associated email campaigns, and monitoring network logs for connections to 104.21.83.249.
Given the domain's age and current active status, it may be repurposed for phishing attacks, and proactive blocking at the DNS or web gateway level is recommended. No additional details about the phishing kit, target brand, or scam category are available in this evidence set, so analysis should focus on observed behavior and any new threat intelligence feeds.