https://maxquadsnew.info/w/dVmJFyuoiHTTP 200
8.9 KB
3.3 KB
0 internal · 0 external
Server: nginx/1.27.5Content-Type: text/html; charset=utf-8All stored response-header names (6)
ServerDateContent-TypeContent-LengthConnectionEtag“maxquadsnew.info”
maxquadsnew.info — Erro no servidor (HTTP 502). Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, SOCRadar, Yandex Safebrowsing); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 88/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
maxquadsnew.info was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and first observed on July 31 2026. The domain resolves to the IPv4 address 93.152.223.244 and uses Cloudflare DNS services (ed.ns.cloudflare.com, june.ns.cloudflare.com). VirusTotal reports that the domain has been scanned by 91 AV engines, none of which have issued a detection at the time of analysis. The domain is currently listed on a single security blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one threat‑intelligence source has classified it as malicious.
The risk level is marked as “under investigation” and the operational status is “active,” suggesting that the infrastructure may still be in use. No public page title, SSL certificate details, or HTTP response codes have been disclosed, so the content served by the site cannot be verified. Consequently, the specific brand or service being spoofed remains unknown, and the exact phishing technique employed cannot be confirmed. The presence of Cloudflare nameservers does not preclude malicious use, but it does provide a level of abstraction that can hinder direct attribution.
Defenders should add 93.152.223.244 and maxquadsnew.info to outbound and inbound filtering rules, monitor DNS queries for the domain, and consider extending existing URL filtering policies to block the domain across all browsers and email gateways. Continuous re‑scanning on VirusTotal and periodic checks against additional blocklists are recommended to capture any future detections. Organizations that employ strict email authentication (DMARC, SPF, DKIM) should verify that any messages claiming to originate from this domain fail authentication, and should quarantine or reject such messages. Because the domain is newly created, threat‑intel feeds may surface additional indicators; security teams should revisit this indicator regularly until the investigation is closed.
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | maxquadsnew.info |
malicious | Sinkholed |
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaTimestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
https://maxquadsnew.info/w/dVmJFyuoiServer: nginx/1.27.5Content-Type: text/html; charset=utf-8ServerDateContent-TypeContent-LengthConnectionEtagPD-20260801-B248B2 Recipient: abuse@identitydigital.com Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraEnvie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarRelatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMonitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo