Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
nexte-amm[.]cc
“Nexte: One-Stop Global Investment Platform | Forex | Commodities | Stocks | Indices | Cryptocurrenc…”
nexte-amm.cc — 未验证. 诈骗类型:Investment Scam. 证据摘要: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 89/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain nexte-amm.cc was registered on May 06, 2026 through Gname.com Pte. Ltd. and continues to resolve to the IP address 104.21.13.61, which belongs to the Cloudflare network (AS13335). The site is served over HTTPS using a Let’s Encrypt certificate (E7) and returns HTTP 200 on request. Both authoritative and recursive DNS queries resolve to the Cloudflare nameservers ruben.ns.cloudflare.com and serenity.ns.cloudflare.com.
The landing page presents itself as “Nexte: One‑Stop Global Investment Platform” and lists services such as forex, commodities, stocks, indices, cryptocurrencies, gold and oil. This branding closely mirrors legitimate investment‑related services, indicating a deliberate brand‑impersonation attempt aimed at luring victims into an investment scam. The page title and the listed asset classes are consistent with the declared target brand of “Investment Scam”.
Open‑source threat feeds have recorded the domain in at least one AlienVault OTX pulse and it appears on three public blocklists. Independent analysis platforms have assigned a Gridinsoft trust score of 0 out of 100, and three of ninety‑five VirusTotal scanners have flagged the domain as malicious. The combination of a low trust score, blocklist listings, and partial VirusTotal detection underscores a high confidence that the domain is being used for fraudulent activity.
Defenders should add nexte-amm.cc to network‑level deny lists and configure web filters to block HTTP and HTTPS traffic to the associated IP address. Continuous monitoring of DNS queries for the domain and its Cloudflare nameservers is advised to detect any re‑use or pivot attempts. Incident response teams should treat any communications referencing the Nexte branding as suspect and advise users to avoid providing personal or financial information to the site.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
网站配置分析
证据与外部报告
PD-20260623-C1FBFC Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。