allenfortlimited[.]ltd
“Bot Verification”
allenfortlimited.ltd — Contenuto non disponibile. Simulazione del marchio: Coinbase. Riepilogo delle prove: VirusTotal 1/95 (SOCRadar); PhishDestroy score 55/100. Registrar: Porkbun.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain www.allenfortlimited.ltd is currently active and classified as a high‑risk brand‑impersonation campaign targeting Coinbase. The site returns an HTTP 307 redirect and presents a page titled "Bot Verification" under a Let’s Encrypt R12 certificate. The phishing kit in use has been identified as a Verification Scam, which is consistent with the observed page title.
Infrastructure analysis reveals that the domain resolves to the IPv4 address 198.251.89.220, which is advertised as belonging to AS53667 FranTech Solutions in the United States. The domain was registered on July 02, 2025 through Porkbun LLC and employs the authoritative nameservers ns27.asurahosting.com and ns28.asurahosting.com. The host operates a LiteSpeed web server with a Python/Django stack, and client‑side components include jQuery, Smartsupp, HSTS, and HTTP/3 support.
Detection signals indicate that the site is listed on a single security blocklist, carries a Gridinsoft trust score of 0/100, and has been blocked by the PhishDestroy service. VirusTotal reports a single positive detection out of 95 scanned security vendors, suggesting limited but concrete awareness of the malicious activity. The overall low detection density underscores the need for proactive monitoring, as the campaign may not yet be widely propagated.
Defenders should block the resolved IP address 198.251.89.220 and the domain www.allenfortlimited.ltd at perimeter defenses, update any URL filtering policies to include the full domain, and monitor for traffic to the associated nameservers. Continuous re‑evaluation of VirusTotal and blocklist status is advised, as additional detections may emerge. Given the verified impersonation of Coinbase, organizations handling cryptocurrency credentials should treat any outbound or inbound communications involving this domain as malicious and enforce strict authentication controls.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 7 identified
High-performance web server compatible with Apache configurations.
Live chat and visitor recording tool for customer support.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of allenfortlimited.ltd · checked Mar 2, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo