# maharuh.com — SUSPICIOUS > PhishDestroy identifies maharuh.com as a credential theft site with 0/95 VirusTotal detections. Do not enter personal data. Verify before clicking. ## Summary PhishDestroy has identified maharuh.com as a credential theft domain posing under the guise of UAE labor recruitment services. The threat involves fraudulent web forms designed to harvest login credentials and personal information from unsuspecting job seekers. This is not generic phishing—it is a targeted credential theft campaign using social engineering to impersonate a legitimate recruitment office in the UAE. The domain’s active status and deceptive page title (mentioning worker recruitment and contact numbers) strongly suggest it is part of a broader campaign targeting Arabic-speaking users seeking domestic employment opportunities. Risk is elevated due to the combination of low detection rates and the use of plausible thematic content. This domain was flagged with 0 detections out of 95 VirusTotal engines as of the latest scan, indicating limited recognition by automated security tools. It was registered on March 14, 2024, through NAMECHEAP INC, resolving to IP address 188.114.96.3. The SSL certificate issuer is Google Trust Services, which does not inherently validate the site’s legitimacy. Notably, the domain remains active and unlisted on major blocklists such as Google Safe Browsing or PhishTank at this time. The combination of recent registration, low detection rate, and use of HTTPS creates a deceptive appearance of trustworthiness despite malicious intent. To mitigate exposure to this credential theft site, users should avoid interacting with any login or input forms on maharuh.com, especially those requesting personal or employment-related details. Organizations should consider blocking the domain and IP at the network level to prevent access from corporate endpoints. End users are advised to verify job offers through official channels and use tools such as browser-based URL inspectors or threat intelligence platforms before submitting sensitive data. The current risk level is under investigation, but evidence strongly supports proactive blocking and user caution. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP ?) - Page title: مكتب استقدام عمال الإمارات 0553854404 شغالات بالشهر - عاملات للتنازل ## Domain Intelligence - Registered: 2024-03-14 16:07:53 - Registrar: NAMECHEAP INC - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/87a0ab2c-f9f2-4431-95cb-fa9c2502141e - PhishDestroy: https://phishdestroy.io/domain/maharuh.com/ - LLM endpoint: https://phishdestroy.io/domain/maharuh.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/maharuh.com/ Last updated: 2026-04-12