Analysis indicates that the domain valoskin.one is an active high-risk phishing site targeting online skincare shoppers. Registered on June 16, 2026, through Global Domain Group LLC, the domain currently resolves to IP address 158.94.211.169 and is served by nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, a pattern commonly associated with bulletproof hosting providers. As of July 31, 2026, the domain appears on one security blocklist and is explicitly blocked by PhishDestroy. VirusTotal scans show that 2 of 91 security vendors flag the domain as malicious, though the specific detection labels and methodologies remain undisclosed.
Infrastructure analysis reveals that the domain was created less than two months prior to the report date, a characteristic consistent with short-lived phishing campaigns. The use of DNSPod nameservers and a hosting provider with a history of abuse further supports the assessment of malicious intent. While the exact content of the site has not yet been fully analysed, the domain name and available threat intelligence suggest it is designed to impersonate a legitimate skincare or cosmetic retailer, likely harvesting payment details or personal information from victims under the guise of a checkout process. Defenders should treat this domain as actively hostile.
Network-level blocking of 158.94.211.169 and the domain itself is recommended. Organisations should also monitor for connections to the DNSPod nameservers, particularly in environments where skincare or e-commerce transactions are common. Given the domain's recent registration and limited detection coverage, it is likely still in the early stages of deployment, and further monitoring of related infrastructure is advised. No evidence currently links this domain to a known phishing kit or specific threat actor group.