Ir al informe de seguridad
Checked 09/08/2026 Ref 7AB434CE

MALICIOUS — CRITICAL

api[.]allegrostatus[.]pl

The domain api.allegrostatus.pl is currently active and continues to be used in a generic phishing campaign.

95/100 evidence score · Critical
VirusTotal
19/91
Blocklists
No stored match
Disponibilidad
Último activo conocido · HTTP 406
Report / Add Evidence Appeal this listing
2026-07-30 12:24 UTCÚltimo activo conocido · HTTP 406

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Este dominio ha sido señalado como malicioso
Motores de seguridad que informan una detección: 19. Tenga extrema precaución: no ingrese credenciales o información personal.
Jump to section
Resumen del informe

api.allegrostatus.pl — Último activo conocido (HTTP 406). Suplantación de marca: Microsoft; Tipo de estafa: Impersonation. Resumen de las pruebas: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Registrador: Corporation Service Company.

El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.

Evidence Analysis

Ref 7AB434CE

The domain api.allegrostatus.pl is currently active and continues to be used in a generic phishing campaign. Registration data shows the domain was created on 27 May 2019 through Corporation Service Company, a common registrar for malicious infrastructure. The authoritative nameservers are ns-cloud-c1.googledomains.com, ns-cloud-c2.googledomains.com, and ns-cloud-c3.googledo, indicating reliance on Google Cloud DNS services. DNS resolution points to the IP address 151.101.1.91, an address that is part of the Fastly content‑delivery network and is frequently leveraged by threat actors to host malicious payloads because of its reputable hosting profile.

VirusTotal analysis reports that 12 of 91 security vendors have flagged the domain, providing independent corroboration of its malicious nature. In addition, the domain appears on at least one external security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, confirming that defensive communities have identified it as a threat. No public evidence regarding SSL certificates, HTTP response codes, page titles, or content has been released, so the exact phishing vector and targeted brand remain unknown. The lack of visible page‑level intelligence limits attribution of the specific lure used, but the classification as generic phishing suggests the site is likely employed to harvest credentials or other sensitive data.

Defenders should add the domain and its resolving IP to their deny‑list rules, monitor for outbound connections to 151.101.1.91, and ensure that email filters are updated to block any messages referencing the domain or its sub‑domains. Continuous re‑scanning on VirusTotal and periodic checks against emerging blocklists are recommended to capture any changes in detection scores. Organizations that use Google Cloud DNS should review any internal sub‑domains that resolve to the same name‑server set for potential compromise.

VirusTotal
VirusTotal
19 det.
URLQuery
URLQuery
3 threat alerts
CF Radar
Malicioso
URLScan
URLScan
ScamAdviser
Scamadviser
80/100
Certificado TLS
Let's Encrypt
Edad
7.2 yr
Estado observado
Último activo conocido 406
PhishDestroy
DestroyList
En lista
Reports Sent
1
Cobertura de los datos13 recorded checks
VirusTotal 19 / 91 URLQuery 3 threat-system alerts PhishStats no comprobado OTX no community references CF Radar provider verdict: malicious URLScan capture informe almacenado URLScan verdict malicious Bloqueos de DNS no comprobado TLS valid certificate, 83d WHOIS 88 mo old Captura de pantalla 3 captures · 3 sources Cadena de redireccionamientos no sondeado Scamadviser 80/100
Inteligencia de seguridad de red
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
DNS4EU api.allegrostatus.pl malicious Sinkholed
Cloudflare DNS api.allegrostatus.pl malicious Sinkholed
OpenDNS api.allegrostatus.pl phishing Phishing Block
CF Cloudflare Radar Verdict Malicioso
Phishing

Proceso de respuesta ante amenazas Pipeline

Descubrimiento
Checks
Reports
Disponibilidad
18/19
Sent Report Recorded
Stored sent-report record for registrar Corporation Service Company, hosting provider, 1 abuse contact
abuse@fastly.com
30/07/2026

Estado de la lista de bloqueados pública

Captura guardada

Inteligencia de dominios

Dominio
URLScan Verdict Malicioso score 100 Phishing brand: Allegro report ↗
Servidor / ASN Heroku · AS54113 Fastly, Inc.
IP Context Fastly shared edge origin IP hidden La reputación de Edge-IP no se atribuye a este dominio.
Registrar (base domain) Corporation Service Company
Dirección IP 151.101.1.91 CDN
UbicaciónCA Montreal, CA
RedAS54113 · Fastly, Inc.
La IP de origen está oculta detrás de un proxy CDN. Los resultados de IP inversa para la dirección perimetral contienen inquilinos no relacionados; encontrar el origen requiere DNS pasivo o datos de transparencia de certificado.
Registration (base domain)allegrostatus.pl · Creado 27/05/2019 Expires 27/05/2027
Estado HTTP406 Error
Elapsed Since First Report 21h
Qué contabilizamos Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Último activo conocido.
Qué contiene cada informe Los registros de informes salientes almacenados pueden hacer referencia a evidencia disponible en ese momento, como veredictos de proveedores, datos de registro, detalles de alojamiento, clasificaciones o capturas de pantalla. Esta página no infiere la carga útil entregada, el recibo, el acuse de recibo o la acción exacta por parte de un destinatario.
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Primera detección30/07/2026
DOM Analysisanalyzed 30/07/2026score 88/1002 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://api.allegrostatus.pl/
Servidores de nombresns-cloud-c1.googledomains.comns-cloud-c2.googledomains.comns-cloud-c3.googledomains.comns-cloud-c4.googledomains.com
TLS Fingerprint
TLS Observationvalid from 23/07/2026scanned 30/07/2026
Favicon Hash
Case ID
Título de la página
Allegro Rest API Status Page
Impersonates
Microsoft Slack
Certificado TLS
Valid transport encryption · Emitido por Let's Encrypt · valid for 83 days
Cruce de inteligencia de amenazas · source references
ScamAdviser Public lookup
A public ScamAdviser lookup is available. Review its current score and warnings at the source; the existence of a lookup page is not itself a malicious verdict.
View on ScamAdviser
Live-fetched via CF worker proxy pool · cached 24h
Tecnologías · 3 identified
Varnish
Caching

Varnish is a reverse caching proxy.

www.varnish-cache.org 100 % de confianza
HSTS
Seguridad

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100 % de confianza
Google Analytics
Analytics

Google Analytics is a free web analytics service that tracks and reports website traffic.

google.com 100 % de confianza
Detected via Cloudflare Radar · Wappalyzer engine
Denunciar este dominio Envía pruebas y ayuda a proteger a los demás

Análisis de VirusTotal

19 / Los proveedores de seguridad de 91 marcaron este dominio
View on VT
Last analyzed First positive detection Previous stored snapshot: 12 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
Cluster25
CRDF
ESET
Emsisoft
Forcepoint ThreatSeeker
G-Data
Gridinsoft
Kaspersky
LevelBlue
Lionic
Netcraft
Seclookup
SOCRadar
Sophos
VIPRE
Webroot

Evidencias archivadas

Wayback Machine Snapshot
Una instantánea histórica está disponible para revisión de evidencia.
View Archive
Análisis del rendimiento del sitio

Google PageSpeed Insights — mobile performance audit of api.allegrostatus.pl · checked Jul 30, 2026

73
Needs Work
Performance
FCP
3.46s
First Contentful Paint
LCP
3.61s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
405ms
Total Blocking Time
SI
3.46s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Stored Capture Evidence 1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: http://api.allegrostatus.pl/
Final URL: https://api.allegrostatus.pl/
Allegro Rest API Status Page
Keep up to date with any unavailability that may affect you.
Respuesta
HTTP 200
HTML body
107.3 KB
Compressed
15.9 KB
Links
50 internal · 4 external
Detected technologies
bootstrap
Selected response headers
Server: Heroku
Cache-Control: max-age=0, public, must-revalidate, s-maxage=600
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Security headers present
Strict-Transport-SecurityContent-Security-PolicyX-Frame-OptionsX-Content-Type-OptionsX-XSS-ProtectionCross-Origin-Opener-Policy
HSTS: observed DNSSEC: not observed WAF / firewall: observed Cloaking flag: not observed
Favicon fingerprint: 8f277cec01b775f9393bd063b6f6f9d26784b2d8dd69466a5e092518de81d0ac
All stored response-header names (29)
ConnectionContent-Lengthx-content-type-optionsServerEtagx-frame-optionsx-runtimeCache-Controlx-request-idViax-xss-protectionx-permitted-cross-domain-policiescontent-security-policyx-download-optionsnelcross-origin-opener-policyreport-toContent-Typereporting-endpointsContent-EncodingAccept-RangesEdadDateX-Served-ByX-CacheX-Cache-HitsX-TimerVaryStrict-Transport-Security
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.

Europol
Encuentre el canal de denuncia oficial para su país de la UE
National police directory
¡Cuidado con los estafadores que se hacen pasar por empresas de recuperación de datos! Los delincuentes pueden volver a contactar a las víctimas haciéndose pasar por investigadores, abogados o agentes de recuperación. No pague tarifas por adelantado ni comparta credenciales. Más información sobre el fraude en las ayudas de recuperación →

Informa a las autoridades locales

Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.

directorio de 97 países
Borrador asistido por IA: el proveedor de IA procesa los detalles del incidente Revíselo y envíelo usted mismo
Incrustar este informeRead-only HTML widget
HTML · IFRAME

Incrustar este informe

Comparte esta información sobre amenazas en tu página web o blog

embed.html
<iframe
  src="https://phishdestroy.io/es/embed/domain/api.allegrostatus.pl"
  title="PhishDestroy threat report for api.allegrostatus.pl"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>