nexus-market[.]nexus
“Nexus Market â Official Nexus Darknet Market [2026]”
nexus-market.nexus — Non verificato. Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Registrar: Tucows Domains.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain nexus-market.nexus is currently active and serves a page titled “Nexus Market — Official Nexus Darknet Market [2026]”. The site returns HTTP 200 and is classified as a high‑risk generic phishing operation. Its recent creation date of 14 May 2026 indicates a short lifespan typical of fast‑flux phishing infrastructure. Technical resolution shows the hostname resolves to the IPv4 address 188.114.96.3, which is hosted by a CDN provider located in Canada. Authoritative nameservers are two distinct DNS servers that belong to the same CDN network. The site presents a TLS certificate issued by a widely‑trusted public certificate authority, with the certificate chain terminating in a well‑known root, confirming the use of a legitimate‑looking HTTPS endpoint. Open‑source threat feeds have already flagged the domain. VirusTotal records three of ninety‑five scanning engines as malicious, and the domain appears on a single security blocklist. An AlienVault OTX pulse references the domain once, and the Gridinsoft trust scoring system assigns it a 0 out of 100 rating, reinforcing the malicious reputation. The domain is also listed by an anti‑phishing feed that actively blocks it. Publicly available information does not disclose the underlying operators, nor does it link the site to a known phishing kit or malware payload. The page mimics a darknet marketplace, suggesting social engineering aimed at credential theft or financial fraud, but the exact victim profile and lure tactics remain uncertain. Defenders should treat nexus-market.nexus as hostile. Immediate actions include adding the domain to network‑level deny lists, updating email gateway filters to block URLs and sender domains that resolve to the same IP, and monitoring DNS queries for any new sub‑domains pointing at 188.114.96.3. Continuous threat‑intel feeds should be consulted for any emerging indicators related to this infrastructure.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo