Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
nexotexfx[.]ltd
“nexotexfx.ltd - Home”
Сохранённое обнаружение
Обнаружена маскировка
- Тип маскировки
status_split- Оценка маскировки
- 2/6
Сводка доказательств
The domain nexotexfx.ltd has been identified as a credential harvesting phishing site targeting users of the OLITT platform. Analysis indicates the domain is currently offline, though it previously hosted a fraudulent login portal designed to capture sensitive authentication details. The threat type is classified as generic phishing with an elevated risk level due to its deceptive infrastructure and targeting of user credentials. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NameSilo, LLC, and resolves to the IP address 151.80.4.15. It appears on one security blocklist and is flagged by 3 of 95 security vendors on VirusTotal. The domain holds a Gridinsoft trust score of 0/100, indicating no legitimate reputation. It employs an SSL certificate issued by DigiCert Inc, which may be used to lend false credibility to the phishing attempt. Detected technologies include Google Cloud, Nginx, and Google Cloud CDN, suggesting the use of cloud-based hosting to evade detection and enhance scalability. Current status confirms the domain has been taken offline, reducing immediate risk to users. However, the infrastructure remains registered and could be reactivated. Organizations and individuals are advised to block the domain and its associated IP (151.80.4.15) at the network perimeter. Security teams should monitor for related domains registered through NameSilo or resolving to the same IP range. Users who may have interacted with the domain should reset credentials for any accounts accessed during the exposure window and enable multi-factor authentication where available. Proactive threat hunting for indicators of compromise, including the domain name and SSL certificate details, is recommended to identify potential breaches.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260207-A49762- Заголовок сохранённой страницы
- OLITT
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Section 3.1 of the AUP: The domain nexotexfx.ltd is engaged in phishing activities, which are explicitly prohibited under your Acceptable Use Policy.
Section 5.2 of the TOS: The registrar reserves the right to suspend services for any fraudulent activities; the operation of this domain constitutes a clear violation of this provision.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant given the phishing nature of the domain.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud using electronic communications, applicable to the fraudulent activities associated with this domain.
Anti-Phishing Consumer Protection Act: This act aims to combat phishing by imposing penalties on those who engage in deceptive practices to obtain sensitive information.
Regulatory Note: Failure to take immediate action against this domain may result in legal repercussions for non-compliance with both your internal policies and applicable laws. It is imperative to act swiftly to mitigate potential liability.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 3 технологии с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание