rituals-happy[.]com
“Cosmetics – Affordable Beauty for Everyone”
Resumen de las pruebas
The domain rituals-happy.com was registered on 21 February 2026 via NiceNIC International Group Co., Limited and resolves to the IPv4 address 86.54.24.33, which is advertised as being located in Lithuania under ASN 208885 (Noyobzoda Faridduni Saidilhom). The site presents a page titled “Cosmetics – Affordable Beauty for Everyone” and serves content over HTTPS using a Let’s Encrypt R12 certificate. The web server is identified as LiteSpeed supporting HTTP/3, and the front‑end stack includes Eleventy and Bootstrap. Authoritative nameservers are ns3.my-ndns.com and ns4.my-ndns.com. The domain has been added to at least one public blocklist and is actively blocked by the PhishDestroy service.
Gridinsoft assigns a trust score of 0 out of 100, indicating a high confidence of malicious intent. VirusTotal reports that 4 of 93 scanned security vendors flag the domain, reinforcing the suspicion. The detection profile, combined with the generic cosmetics‑oriented page title, aligns with a generic phishing campaign that likely attempts to harvest credentials or payment information under the guise of a beauty‑related service. The infrastructure choices—fastly‑deploying LiteSpeed with HTTP/3 and using a free Let’s Encrypt certificate—are typical of short‑lived phishing operations that aim to appear legitimate while minimizing operational cost.
At the time of reporting (22 July 2026) the host is offline, but the observed indicators suggest the domain could be re‑activated or duplicated in future campaigns. Defenders should continue to monitor the IP address 86.54.24.33 and the associated ASN for any resurgence, ensure that web filtering solutions ingest the blocklist entry, and add the domain to internal deny lists. Network traffic to the nameservers ns3.my-ndns.com and ns4.my-ndns.com should be flagged, and any outbound connections to the domain should be logged and inspected for credential‑stealing attempts.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.