The domain nexus-url.digital was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on July 25, 2026. DNS resolution points to the Cloudflare‑managed address 104.21.38.127, with authoritative nameservers adel.ns.cloudflare.com and javon.ns.cloudflare.com. The site presents a TLS certificate issued by Google Trust Services under the WE1 root, which validates the HTTPS connection but does not mitigate the observed malicious behavior. VirusTotal analysis shows that one out of ninety‑one scanning engines flagged the domain, indicating at least one vendor has identified it as malicious.
The domain is listed on a single external blocklist and is actively blocked by the PhishDestroy service, confirming that threat‑intelligence feeds consider it a phishing source. No additional public signals such as Safe Browsing alerts, Open Threat Exchange entries, or known phishing kit fingerprints have been published for this host. The lack of published page title, HTTP response codes, or content hashes leaves the exact phishing payload unknown. Consequently, defenders can reliably infer that the infrastructure is being used for a generic phishing campaign, but the specific lure, target brand, or victim profile remains uncertain.
Recommended mitigations include adding the domain to network‑level deny lists, configuring web‑proxy filters to block HTTPS traffic to the IP address 104.21.38.127, and monitoring DNS queries for the Cloudflare nameservers. Continuous re‑scanning with multi‑engine services such as VirusTotal is advised to capture any escalation in detection counts. Incident response teams should also correlate internal logs for any authentication attempts or credential submissions directed at this host, as the short domain age suggests a rapidly deployed campaign.