https://maxquadsnew.info/w/dVmJFyuoiHTTP 200
8.9 KB
3.3 KB
0 internal · 0 external
Server: nginx/1.27.5Content-Type: text/html; charset=utf-8All stored response-header names (6)
ServerDateContent-TypeContent-LengthConnectionEtag“maxquadsnew.info”
maxquadsnew.info was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and first observed on July 31 2026. The domain resolves to the IPv4 address 93.152.223.244 and uses Cloudflare DNS services (ed.ns.cloudflare.com, june.ns.cloudflare.com). VirusTotal reports that the domain has been scanned by 91 AV engines, none of which have issued a detection at the time of analysis. The domain is currently listed on a single security blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one threat‑intelligence source has classified it as malicious.
The risk level is marked as “under investigation” and the operational status is “active,” suggesting that the infrastructure may still be in use. No public page title, SSL certificate details, or HTTP response codes have been disclosed, so the content served by the site cannot be verified. Consequently, the specific brand or service being spoofed remains unknown, and the exact phishing technique employed cannot be confirmed. The presence of Cloudflare nameservers does not preclude malicious use, but it does provide a level of abstraction that can hinder direct attribution.
Defenders should add 93.152.223.244 and maxquadsnew.info to outbound and inbound filtering rules, monitor DNS queries for the domain, and consider extending existing URL filtering policies to block the domain across all browsers and email gateways. Continuous re‑scanning on VirusTotal and periodic checks against additional blocklists are recommended to capture any future detections. Organizations that employ strict email authentication (DMARC, SPF, DKIM) should verify that any messages claiming to originate from this domain fail authentication, and should quarantine or reject such messages. Because the domain is newly created, threat‑intel feeds may surface additional indicators; security teams should revisit this indicator regularly until the investigation is closed.
PD-20260801-B248B2| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | maxquadsnew.info |
malicious | Sinkholed |
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
أول قيمة محفوظة: يمكن الوصول إليه
يمكن الوصول إليه ← يتعذر الوصول إليه
يتعذر الوصول إليه ← يمكن الوصول إليه
يمكن الوصول إليه ← يتعذر الوصول إليه
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
حُدّدت تقنية واحدة عالية الثقة
Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
https://maxquadsnew.info/w/dVmJFyuoiServer: nginx/1.27.5Content-Type: text/html; charset=utf-8ServerDateContent-TypeContent-LengthConnectionEtagإذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنأرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةراقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب