The domain api.allegrostatus.pl is currently active and continues to be used in a generic phishing campaign. Registration data shows the domain was created on 27 May 2019 through Corporation Service Company, a common registrar for malicious infrastructure. The authoritative nameservers are ns-cloud-c1.googledomains.com, ns-cloud-c2.googledomains.com, and ns-cloud-c3.googledo, indicating reliance on Google Cloud DNS services. DNS resolution points to the IP address 151.101.1.91, an address that is part of the Fastly content‑delivery network and is frequently leveraged by threat actors to host malicious payloads because of its reputable hosting profile.
VirusTotal analysis reports that 12 of 91 security vendors have flagged the domain, providing independent corroboration of its malicious nature. In addition, the domain appears on at least one external security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, confirming that defensive communities have identified it as a threat. No public evidence regarding SSL certificates, HTTP response codes, page titles, or content has been released, so the exact phishing vector and targeted brand remain unknown. The lack of visible page‑level intelligence limits attribution of the specific lure used, but the classification as generic phishing suggests the site is likely employed to harvest credentials or other sensitive data.
Defenders should add the domain and its resolving IP to their deny‑list rules, monitor for outbound connections to 151.101.1.91, and ensure that email filters are updated to block any messages referencing the domain or its sub‑domains. Continuous re‑scanning on VirusTotal and periodic checks against emerging blocklists are recommended to capture any changes in detection scores. Organizations that use Google Cloud DNS should review any internal sub‑domains that resolve to the same name‑server set for potential compromise.