rilakrevolution.ca - malicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned rilakrevolution.ca and returned a malicious verdict (score 62), categorised as phishing. The page resolved to 3.33.130.190 on Amazon Technologies Inc. in US. The domain was registered 4592 days ago through Go Daddy Domains Canada, Inc. 5 domains and 5 IPs were contacted, over 20 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 62) · Confidence 68%
- Scanned URL:
https://rilakrevolution.ca/ - Domain: rilakrevolution.ca · IP: 3.33.130.190 · AS16509 · US
- HTTP status: 200 · text/html
- Registrar: Go Daddy Domains Canada, Inc · domain age 4592 days · created 2014-01-25
- TLS issuer: C=US, O=GoDaddy.com, CN=GoDaddy TLS Intermediate CA DV - R1v1 · valid to Dec 25 13: · subject CN=rilakrevolution.ca
- HTTP requests captured: 20 · cookies set: 10 · outgoing links: 2
- Scan tier: standard · observed 2026-08-22 21:28:49 UTC
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Runtime data beacon to csp.secureserver.net
- Domain impersonates revolut (combosquat)
Contacted infrastructure
- 3.33.130.190 - AS16509 Amazon Technologies Inc. (United States)
- 23.33.238.105 - AS20940 Akamai Technologies, Inc. (Australia)
- 108.158.32.110 - AS16509 Amazon.com, Inc. (Australia)
Observed indicators
- rilakrevolution.ca
- img1.wsimg.com
- api.aws.parking.godaddy.com
- csp.secureserver.net
- widget.trustpilot.com
- 3.33.130.190
- 23.33.238.105
- 184.27.43.36
- 52.66.157.198
- 108.158.32.110
- https://rilakrevolution.ca/
- https://rilakrevolution.ca/lander
Questions about rilakrevolution.ca
- Is rilakrevolution.ca safe?
- No. MalwareAnalyzer scanned rilakrevolution.ca on 22 Aug 2026 and returned a malicious verdict with a score of 62 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was rilakrevolution.ca checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of rilakrevolution.ca
Scanned on MalwareAnalyzer by Cyble · Open interactive scan