Analysis indicates that the domain nexus-hub.cfd is currently under investigation as an active phishing portal. Registered on July 25, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain resolves to the IP address 188.114.96.3, which is associated with Cloudflare infrastructure, as further evidenced by its nameservers (adel.ns.cloudflare.com and javon.ns.cloudflare.com). The SSL certificate is issued by Google Trust Services (WE1), a common configuration for both legitimate and malicious sites leveraging Cloudflare services. As of July 28, 2026, the domain appears on one security blocklist, and it has been blocked by PhishDestroy.
However, a scan conducted by 91 vendors on VirusTotal yielded no detections at the time of reporting, though the absence of detections does not confirm the domain's safety. The domain remains active, and its exact content or targeted brand has not yet been analyzed in detail. Defenders are advised to treat this domain with caution, particularly given its recent registration and association with known phishing mitigation services. Infrastructure analysis reveals the use of Cloudflare, which may obscure the true hosting origin and complicate attribution.
The registrar, NICENIC INTERNATIONAL GROUP CO., LIMITED, has been previously linked to domains involved in fraudulent activity, though this alone is not conclusive evidence of malicious intent. Security teams should monitor network traffic for connections to 188.114.96.3 and the domain itself, and consider implementing temporary blocks or alerts for internal users until further analysis is conducted. Additional scrutiny, including sandboxed inspection of the site's behavior, is recommended to determine the nature of the phishing campaign.