Analysis indicates that the domain maxddoomru.com was registered on July 24, 2026 via Dominet (HK) Limited and is currently resolved to the IP address 109.172.89.55. The domain is served through Cloudflare DNS, using the nameservers henrik.ns.cloudflare.com and sierra.ns.cloudflare.com. It appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that threat intelligence sources consider it malicious.
VirusTotal reports that the domain has been scanned by 91 AV engines, none of which returned a detection; this absence of detections should not be interpreted as evidence of benign behavior, only that current signatures have not flagged the site. No public page title, brand impersonation, or additional content metadata is available, leaving the exact phishing lure unknown. The lack of observable brand references limits attribution but the classification as generic phishing remains consistent with the blocklist signals.
Defensive practitioners should add maxddoomru.com to URL filtering policies, DNS sinkhole rules, and endpoint allow‑list exclusions. Continuous monitoring of the IP 109.172.89.55 for any changes in hosting or additional malicious activity is advised, as well as periodic re‑scanning with VirusTotal and other sandbox services to detect potential evolution of payloads. Given the recent creation date, the infrastructure may still be in an early deployment stage, warranting heightened vigilance for any emerging indicators of compromise associated with this domain.