nexus-auth[.]de
“Nexus Authority”
证据摘要
nexus-auth.de is currently observed as an active generic phishing infrastructure. The domain resolves to the IPv4 address 45.81.232.18 and returns an HTTP 303 status, indicating a redirection flow typical of credential‑harvesting sites. The TLS handshake is performed with a Let’s Encrypt R12 certificate, providing encryption but no indication of legitimate ownership.
The hosting environment is tied to the autonomous system AS44486, registered to synlinq.de, and the IP is geolocated in Germany. Name resolution is delegated to ns1.mc-host24.de and ns2.mc-host24.de, both of which are commonly associated with shared hosting services. Reputation scoring from Gridinsoft assigns a zero out of one hundred, reflecting an extremely low trust rating.
Reputation services have flagged the domain. PhishDestroy includes nexus‑auth.de on its blocklist, and the domain appears on one additional security blocklist. AlienVault OTX lists the domain in a single threat‑intelligence pulse. VirusTotal reports that seven out of ninety‑five scanning engines have raised detections, reinforcing the malicious classification.
The publicly available page title is “Nexus Authority,” but no further content analysis is available in the current data set. Consequently, the precise luring technique, targeted brand, or credential‑capture template remains unknown. Analysts should treat the domain as a phishing vector until additional forensic evidence confirms the exact payload.
Defenders are advised to block both the domain name and its resolving IP address at perimeter and DNS layers. Continuous monitoring for new host‑header variations or additional IPs is recommended, as the infrastructure may be expanded. Integrating the domain into internal threat‑intel feeds will aid in rapid detection and mitigation.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
VirusTotal
7 → 9
-
VirusTotal
7 → 9
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of nexus-auth.de · checked Mar 2, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控