nexus-darknet[.]store
“Nexus Market Verified Links 2026: Official Security Guide”
nexus-darknet.store — Erro no servidor (HTTP 502). Resumo das evidências: VirusTotal 2/95 (Fortinet, SOCRadar); PhishDestroy score 71/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, nexus-darknet.store, is identified as a phishing portal targeting users of Nexus Market, a known darknet marketplace. Analysis indicates the site presents itself as an official security guide under the title 'Nexus Market Verified Links 2026: Official Security Guide,' a tactic designed to deceive users into divulging login credentials, payment details, or other sensitive information. The threat type is classified as generic phishing, with no evidence of a specific drainer kit or advanced malware payload at this time. However, the impersonation of a darknet market suggests a high-risk targeting of individuals engaged in illicit or high-value transactions. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with malicious domains. The site resolves to the IP address 176.116.0.112 and employs Nginx as its web server technology. Detection metrics indicate limited but concerning visibility: the domain is flagged by 2 out of 95 security vendors on VirusTotal, holds a Gridinsoft trust score of 0/100, and appears on one security blocklist. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility and lack of cost. No Google Safe Browsing (GSB) detections are currently recorded, though this may reflect a delay in propagation or evasion techniques. As of the latest assessment, nexus-darknet.store has been taken offline, likely in response to security vendor interventions or registrar enforcement actions. Despite its current inactive status, the domain remains a residual risk due to the potential for re-registration or migration to alternative infrastructure. Users who interacted with the site are advised to immediately invalidate any credentials or payment details shared, monitor for unauthorized transactions, and employ multi-factor authentication on all accounts. Organizations should update blocklists to include the domain and associated IP address, while security teams are encouraged to analyze network logs for connections to 176.116.0.112 during the period of activity. The elevated risk level persists due to the targeted nature of the phishing campaign and the high-value user base it seeks to exploit.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 12:54:05 UTC
Tecnologias · 1 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of nexus-darknet.store · checked Jun 26, 2026
Evidências e relatórios externos
PD-20260214-802996 Recipient: abuse@nicenic.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo