nexus-url[.]cfd
“Nexus Market • verified mirror routing and uptime tracking”
Зведення доказів
Analysis of nexus-url.cfd indicates that the domain is actively being used for a generic phishing campaign. The domain was registered on July 25, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolved to the IP address 188.114.97.3, which is owned by CloudFlare, Inc. and geolocated to Canada. The hosting arrangement uses CloudFlare nameservers adel.ns.cloudflare.com and javon.ns.cloudflare.com, a common pattern for fast‑flux or proxy‑based phishing infrastructures.
The site is protected by an SSL certificate issued by Google Trust Services, a legitimate certificate authority often leveraged by malicious actors to increase user trust. Security telemetry shows that the domain is blocked by PhishDestroy and appears on one external security blocklist, demonstrating that at least one threat‑intelligence feed has flagged it. VirusTotal reports a single positive detection out of 91 scanned security vendors, confirming that at least one vendor has identified malicious behavior.
No additional public analysis, such as page title or content inspection, is currently available, leaving the precise phishing lure and targeted brand unspecified. Defenders should treat the domain as hostile: network firewalls and DNS filtering should be configured to block nexus-url.cfd and its resolved IP, logging of any outbound connections to the domain should be enabled, and the domain should be added to internal blocklists. Continuous monitoring of related CloudFlare‑hosted IPs and the registrar’s recent registrations is advised to detect potential sibling domains that may share the same infrastructure.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260728-BB126B- PDF-файл
- PDF із доказами
Повний текст доказів
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Перший запис
Перше збережене значення: Доступний
-
VirusTotal
0 → 1
-
Статус домену
Доступний → Недоступний
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 3 технології з високою впевненістю
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of nexus-url.cfd · checked Jul 28, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога