Analysis of maximas.app, first observed on June 08, 2026, shows infrastructure typical of a newly‑registered phishing campaign. The domain is delegated to Cloudflare name servers marjory.ns.cloudflare.com and rocco.ns.cloudflare.com, indicating use of Cloudflare's DNS and CDN services. DNS resolution points to the IPv4 address 188.114.97.3, an IP owned by Cloudflare, which is frequently leveraged by threat actors to mask origin infrastructure. The domain appears on a single public security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one reputable phishing mitigation service considers it malicious.
Registration was performed through TLD Registrar Solutions Ltd, a registrar that does not appear to have a public history of abuse but provides no additional transparency about the registrant. VirusTotal records show the domain was scanned by 91 AV engines, with none reporting a detection; however, the absence of detections does not constitute a safety assurance, as many phishing sites evade static analysis. No public Safe Browsing, OTX, SSL certificate details, HTTP response codes, or page title information are currently available, limiting the ability to assess content‑level risk.
Given the recent creation date, Cloudflare hosting, blocklist presence, and active status, defenders should treat maximas.app as a potential phishing vector. Recommended actions include adding the domain and its resolving IP to network‑level deny lists, monitoring DNS queries for the domain, and conducting a manual content fetch in a sandboxed environment to capture HTTP headers, page title, and any credential‑harvesting forms. Continuous re‑evaluation is advised as additional telemetry, such as detection vendor updates or community reports, become available.