whitelist[.]blockchains-nexo[.]io
“Crypto Loan with Nexo | Get Funds And Keep Your Crypto”
whitelist.blockchains-nexo.io — 服务器错误 (HTTP 502). 品牌冒充:Ethereum; 诈骗类型:Wallet/seed Phishing. 证据摘要: VirusTotal 16/93 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLQuery 4 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain whitelist.blockchains-nexo.io indicates it was a brand-impersonation scam targeting Ethereum users, operational until recently taken offline. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, and resolved to IP 104.21.17.79, hosted on Cloudflare's network (AS13335, United States). No SSL certificate was present, increasing the risk of interception or manipulation of user data. The page title, 'Crypto Loan with Nexo | Get Funds And Keep Your Crypto,' explicitly impersonates Nexo, a known cryptocurrency lending platform, aligning with the classified scam type of wallet/seed phishing.
Security vendors flagged the domain on VirusTotal, with 16 of 93 engines detecting malicious activity, though the exact nature of detections (e.g., phishing, malware distribution) is not specified in available data. The domain appears on two security blocklists and is actively blocked by PhishDestroy and ScamSniffer. Gridinsoft assigned a trust score of 0/100, further corroborating its malicious classification. Nameservers (major.ns.cloudflare.com and novalee.ns.cloudflare.com) are consistent with Cloudflare infrastructure, a common choice for both legitimate services and threat actors due to its privacy and resilience features.
While the domain is currently offline, defenders should treat any future resolution or re-emergence of this infrastructure as high-risk. Organizations are advised to block the domain and its associated IP at the network level, monitor for related subdomains or typosquatting variants, and alert users to the impersonation of Nexo and Ethereum. The absence of SSL and the use of Cloudflare hosting do not inherently indicate malicious activity but are notable in the context of phishing infrastructure. Further investigation into the registrar's response and any historical WHOIS data may provide additional context for takedown or attribution efforts.
网络安全情报 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | whitelist.blockchains-nexo.io |
phishing | Phishing Block |
| Hagezi Threat Feed | whitelist.blockchains-nexo.io |
malicious | Sinkholed |
| DNS4EU | whitelist.blockchains-nexo.io |
malicious | Sinkholed |
| Quad9 DNS | whitelist.blockchains-nexo.io |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
Latest Classified Outcome 2026-08-13 12:53:31 UTC
VirusTotal 分析
证据与外部报告
PD-20260125-2721A1 Recipient: abuse@nicenic.net 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。