https://maxquadsnew.info/w/dVmJFyuoiHTTP 200
8.9 KB
3.3 KB
0 internal · 0 external
Server: nginx/1.27.5Content-Type: text/html; charset=utf-8All stored response-header names (6)
ServerDateContent-TypeContent-LengthConnectionEtag“maxquadsnew.info”
maxquadsnew.info was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and first observed on July 31 2026. The domain resolves to the IPv4 address 93.152.223.244 and uses Cloudflare DNS services (ed.ns.cloudflare.com, june.ns.cloudflare.com). VirusTotal reports that the domain has been scanned by 91 AV engines, none of which have issued a detection at the time of analysis. The domain is currently listed on a single security blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one threat‑intelligence source has classified it as malicious.
The risk level is marked as “under investigation” and the operational status is “active,” suggesting that the infrastructure may still be in use. No public page title, SSL certificate details, or HTTP response codes have been disclosed, so the content served by the site cannot be verified. Consequently, the specific brand or service being spoofed remains unknown, and the exact phishing technique employed cannot be confirmed. The presence of Cloudflare nameservers does not preclude malicious use, but it does provide a level of abstraction that can hinder direct attribution.
Defenders should add 93.152.223.244 and maxquadsnew.info to outbound and inbound filtering rules, monitor DNS queries for the domain, and consider extending existing URL filtering policies to block the domain across all browsers and email gateways. Continuous re‑scanning on VirusTotal and periodic checks against additional blocklists are recommended to capture any future detections. Organizations that employ strict email authentication (DMARC, SPF, DKIM) should verify that any messages claiming to originate from this domain fail authentication, and should quarantine or reject such messages. Because the domain is newly created, threat‑intel feeds may surface additional indicators; security teams should revisit this indicator regularly until the investigation is closed.
PD-20260801-B248B2| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | maxquadsnew.info |
malicious | Sinkholed |
모니터링 중인 외부 피드 10개 · 저장된 스냅샷 2026년 8월 12일
최초 저장값: 접속 가능
접속 가능 → 접속 불가
접속 불가 → 접속 가능
접속 가능 → 접속 불가
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
신뢰도가 높은 기술 1개 식별
Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
https://maxquadsnew.info/w/dVmJFyuoiServer: nginx/1.27.5Content-Type: text/html; charset=utf-8ServerDateContent-TypeContent-LengthConnectionEtag계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
저장된 차단 목록, WHOIS, DNS 및 공개 스캔 증거를 사용한 위협 분석
지금 스캔하기의심스러운 도메인을 당사의 위협 데이터베이스에 신고해 주세요 — 커뮤니티를 보호해 주세요
보고서최근 피싱 보고서 및 관찰된 가용성 변경 사항
모니터링