https://maxquadsnew.info/w/dVmJFyuoiHTTP 200
8.9 KB
3.3 KB
0 internal · 0 external
Server: nginx/1.27.5Content-Type: text/html; charset=utf-8All stored response-header names (6)
ServerDateContent-TypeContent-LengthConnectionEtag“maxquadsnew.info”
maxquadsnew.info was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and first observed on July 31 2026. The domain resolves to the IPv4 address 93.152.223.244 and uses Cloudflare DNS services (ed.ns.cloudflare.com, june.ns.cloudflare.com). VirusTotal reports that the domain has been scanned by 91 AV engines, none of which have issued a detection at the time of analysis. The domain is currently listed on a single security blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one threat‑intelligence source has classified it as malicious.
The risk level is marked as “under investigation” and the operational status is “active,” suggesting that the infrastructure may still be in use. No public page title, SSL certificate details, or HTTP response codes have been disclosed, so the content served by the site cannot be verified. Consequently, the specific brand or service being spoofed remains unknown, and the exact phishing technique employed cannot be confirmed. The presence of Cloudflare nameservers does not preclude malicious use, but it does provide a level of abstraction that can hinder direct attribution.
Defenders should add 93.152.223.244 and maxquadsnew.info to outbound and inbound filtering rules, monitor DNS queries for the domain, and consider extending existing URL filtering policies to block the domain across all browsers and email gateways. Continuous re‑scanning on VirusTotal and periodic checks against additional blocklists are recommended to capture any future detections. Organizations that employ strict email authentication (DMARC, SPF, DKIM) should verify that any messages claiming to originate from this domain fail authentication, and should quarantine or reject such messages. Because the domain is newly created, threat‑intel feeds may surface additional indicators; security teams should revisit this indicator regularly until the investigation is closed.
PD-20260801-B248B2| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | maxquadsnew.info |
malicious | Sinkholed |
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
İlk kayıtlı değer: Erişilebilir
Erişilebilir → Erişilemiyor
Erişilemiyor → Erişilebilir
Erişilebilir → Erişilemiyor
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
1 yüksek güvenli teknoloji belirlendi
Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
https://maxquadsnew.info/w/dVmJFyuoiServer: nginx/1.27.5Content-Type: text/html; charset=utf-8ServerDateContent-TypeContent-LengthConnectionEtagHesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraŞüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirSon kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleCanlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin