OSINT Portfolio / Case 010
P1 Critical Polish Marketplace Phishing · Card Harvesting · PhaaS Platform

basicmodoralo.com · AllegroLokalnie Verification Portal
3,309 Live URLs · Polish Card Harvesting

A freshly registered PhaaS platform impersonates Allegro Lokalnie — Poland's largest marketplace (21M users) — via an account-restriction social engineering lure. Victims are routed to a fake "Verification Portal" that collects Visa, Mastercard, PayPal and Google Pay credentials. 3,309 URLs verified live by PhishTank on the day of investigation. The platform uses Cloudflare in a dual role: hosting (Cloudflare Pages) and bot protection (CF Bot Management), simultaneously enabling the phishing and blocking all automated research and takedown signals.

AllegroLokalnie Clone Account Restriction Lure Card Harvesting 3,309 Live URLs basicmodoralo.com Cloudflare Pages PhaaS Platform Poland
Entry Domainallegrolokalnie.help
Platformbasicmodoralo.com
Scale3,309 verified live URLs
HostingCloudflare Pages
Platform Registered2026-08-04 · NameSilo
Target BrandAllegro Lokalnie · Poland
Cards TargetedVisa · MC · Maestro · PayPal · Google Pay
Confirmed LiveBelgian Orange IP · 2026-08-16
Update — 2026-08-17

Domain seized. Following this report, NameSilo placed basicmodoralo.com on ClientHold status (ticket #468369) within 24 hours of submission. DNS now returns zero A records and all HTTP connectivity is dead. All 3,309 PhishTank-verified phishing URLs are offline. The full platform — including mx, go, track, admin, panel, and api subdomains — has been neutralised. NameSilo's response: "Thank you for reporting domain: basicmodoralo.com. We have placed the domain on ClientHold status."

Finding 1 — Entry Infrastructure: allegrolokalnie.help → basicmodoralo.com

The campaign entry domain allegrolokalnie.help was registered on 2026-08-15 — one day before this investigation — through Global Domain Group LLC, a registrar used consistently across the phishing domain cluster. The domain resolves to Cloudflare (188.114.96.3) and serves a single purpose: HTTP 302 redirect to the phishing platform.

The redirect target is basicmodoralo.com/mx/n/1855468643 from datacenter IPs, and basicmodoralo.com/n/438227451786911 from Belgian residential IPs — confirming geographic routing in the TDS layer. The /mx/ prefix routes non-EU traffic; Belgian IPs drop directly into the /n/ namespace.

$ curl -sI https://allegrolokalnie.help/ HTTP/2 302 location: https://basicmodoralo.com/mx/n/1855468643 ← datacenter IP route server: cloudflare cf-ray: a2c2ffe75d44d37c-FRA # From Belgian Orange residential IP (browser, incognito): # → https://basicmodoralo.com/n/438227451786911 ← Belgian route WHOIS allegrolokalnie.help: Creation Date: 2026-08-15T11:36:53Z ← 1 day old at investigation time Registrar: Global Domain Group LLC Name Servers: ara.ns.cloudflare.com / martin.ns.cloudflare.com
Fresh domain, fast deployment: A 1-day-old domain with a live redirect to a phishing platform confirms active campaign rollout. The operator registers new domains daily and routes them through the basicmodoralo.com TDS to distribute victim traffic. Domains are disposable — when flagged, a new one replaces it within hours.
Finding 2 — The Platform: basicmodoralo.com — Full PhaaS Infrastructure

basicmodoralo.com was registered on 2026-08-04 through NameSilo with PrivacyGuardian.org shielding the registrant identity. Within 12 days of registration it is operating at scale as a full phishing-as-a-service platform. All infrastructure sits behind Cloudflare Pages (188.114.96.2 / 188.114.97.2) with Cloudflare Bot Management blocking all automated access.

Six operational subdomains are exposed via DNS — each serving a distinct operational function: traffic routing, redirect shortening, victim tracking, operator admin, campaign management, and backend API. This mirrors the architecture of established PhaaS platforms and indicates a purpose-built operation, not a single-campaign deployment.

# DNS enumeration — basicmodoralo.com subdomains mx.basicmodoralo.com188.114.96.3 ← traffic distribution (geographic routing) go.basicmodoralo.com188.114.96.3 ← redirect shortener (victim delivery links) track.basicmodoralo.com188.114.97.3 ← click/conversion tracking admin.basicmodoralo.com188.114.97.3 ← operator admin panel panel.basicmodoralo.com188.114.96.2 ← campaign management interface api.basicmodoralo.com188.114.97.3 ← backend API # WHOIS Registered: 2026-08-04 ← 12 days old at investigation Registrar: NameSilo, LLC Privacy: PrivacyGuardian.org (#ab19c93e) ← identity concealed CT entries: 3 ← only wildcard cert, no subdomain exposure # Bot Management — all subdomains return CF challenge from datacenter IPs: HTTP/2 403 cf-mitigated: challenge ← JS challenge required, curl blocked
Two-registrar separation: The PhaaS platform (basicmodoralo.com) uses NameSilo; the disposable phishing entry domains use Global Domain Group LLC. Separate registrars prevent a single abuse complaint from linking and suspending both the platform and the delivery domains simultaneously — standard operational separation for resilient phishing infrastructure.
Finding 3 — Scale: 3,309 PhishTank-Verified Live URLs — Allegro Domain Pattern

PhishTank — the largest crowdsourced phishing verification database — lists 3,309 verified live URLs targeting Allegro as of 2026-08-16. All follow a consistent naming pattern: allegro[lokalnie].[random-string].[tld]. The TLD spread is broad and uses new-gTLDs that are cheap and fast to register in bulk.

.xyz
~850
.casa
~750
.lol
~550
.lat
~400
.forum
~350
.study
~250
.help
~160
# Sample phishing domains — all pattern-consistent allegrolokalnie.oferta1122738485522.xyz ← 404 (taken down by Cloudflare) allegrolokalnie.pln738.lol ← 302 → allegrolokalnie.pl (neutralised) allegrolokalnie.help ← 302 → basicmodoralo.com ACTIVE allegro.52399129gg.casa ← 200 Apache default (kit path-locked) allegro.1509smart94301.study ← 200 Apache default (kit path-locked) allegro.320029h8h8.forum ← registered 2026-07-15 (oldest in sample) # Campaign link ID space: /n/1855468643 and /n/438227451786911 # Large numeric IDs suggest high campaign volume — millions of links generated
Kit is path-locked against crawlers: Domains serving Apache default pages at root only activate on specific offer paths (e.g. /oferta/id-[slug]) delivered to victims via chat or SMS. Direct access to root returns the Apache default — the phishing page is invisible to automated scanners that don't possess the exact victim link.
Finding 4 — The Phishing Page: Account Restriction Lure + Multi-Brand Card Harvest

Accessed from a Belgian Orange residential IP (incognito browser), the phishing page at basicmodoralo.com/n/438227451786911 presents a "Verification Portal" impersonating Allegro Lokalnie. The lure is an account restriction notice with a 24-hour deadline and a deletion threat — high-urgency social engineering designed to suppress victim hesitation.

The page collects payment credentials via five brand buttons: Visa, Mastercard, Maestro, Discover, PayPal, Google Pay. Clicking any method presents a card entry form. The "Status: Waiting for verification" message creates false legitimacy — implying a backend system is actively monitoring the victim's response.

AllegroLokalnie Verification Portal phishing page — account restriction lure
# Confirmed page content (accessed from Belgian Orange IP, 2026-08-16) Page title: Verification Portal Brand claim: Allegro Lokalnie (avatar + logo) Lure message: "Your account is temporarily restricted." Urgency: "Confirm your bank details within 24 hours" Threat: "Account will be deleted. All sales cancelled." Payment UI: Visa Mastercard Maestro Discover PayPal Google Pay Status text: "Status: Waiting for verification" URL served: https://basicmodoralo.com/n/438227451786911 Access IP: Belgian Orange residential ← page CONFIRMED LIVE Datacenter IP: 403 CF Bot Challenge — page invisible to scanners
Allegro has 21 million registered users in Poland. The account restriction lure targets sellers specifically — they depend on account access for income and are more likely to comply under urgency. The 24-hour window is calibrated to prevent victims from consulting others or verifying with Allegro's real support. PhishTank's 3,309 verified live URLs represents the externally observable surface; the real reach is far larger as victim links delivered via direct messaging are not indexed.
Finding 5 — Cloudflare as Dual-Role Enabler: Host + Shield

This campaign uses Cloudflare in two simultaneous roles that together create a near-impenetrable operational envelope. Role 1 — Host: The phishing platform (basicmodoralo.com and all subdomains) is deployed on Cloudflare Pages (AS13335, 188.114.96.0/24 and 188.114.97.0/24). The real origin server IP is completely masked — no reverse-IP pivot is possible. Role 2 — Shield: Cloudflare Bot Management enforces a JavaScript challenge on every subdomain, blocking all curl-based checks, automated scanners, abuse pipeline bots, and CERT tooling from ever reaching the platform.

The result: the phishing platform is simultaneously hosted by Cloudflare and protected by Cloudflare from the automated systems that would trigger its takedown. Abuse reports to Cloudflare's Trust & Safety team are the single highest-impact remediation path.

basicmodoralo.com platform infrastructure map
# Cloudflare dual-role summary Role 1 — Hosting: Cloudflare Pages IPs: 188.114.96.2 / 188.114.97.2 All subdomains: 188.114.96.x / 188.114.97.x Origin server: HIDDEN — no pivot possible Role 2 — Shield: Bot Management: cf-mitigated: challenge ← JS challenge on all subdomains Effect: automated abuse scanners see 403, not phishing content Effect: PhishTank/VirusTotal bots cannot verify page content Effect: CERT tooling cannot confirm or screenshot the page Geographic routing: Datacenter IPs: → basicmodoralo.com/mx/n/[ID] (bot-challenged, 403) Belgian Orange IP: → basicmodoralo.com/n/[ID] (page served, confirmed live) # Managed challenge — UA spoofing confirmed ineffective (2026-08-16) curl -A "Mozilla/5.0 (Linux; Android 13; SM-A546B)..." -H "Accept-Language: pl-PL" cType: managed ← JS challenge required, 5.6KB challenge page returned ← Android UA + Polish locale headers still blocked — device fingerprinting, not IP only
Abuse report to Cloudflare is highest priority. They control both the hosting layer (Cloudflare Pages) and the protective layer (Bot Management). A single Cloudflare T&S action can simultaneously take down the platform AND remove the bot shield that was protecting it. This is the single most impactful remediation available without law enforcement involvement.
Finding 6 — Live Support Chat Social Engineering: "Emma" Bot + Push-Payment Fraud

Browser screenshots taken 2026-08-16/17 from Belgian incognito Chrome reveal a previously undocumented layer: an automated support chat widget that activates on the card form page. The chat presents a scripted agent named "Emma from Customer Support" and uses two separate messages to pressure victims into entering card details.

Message 1 — Push payment lure: "The buyer has already completed the payment for the order. To receive the funds, please provide your card details and complete a one-time secure identification." This completely inverts the victim's perception — they believe they are receiving money, not surrendering card credentials. Sellers on Allegro Lokalnie are particularly vulnerable because receiving payment notifications is a normal, expected event.

Message 2 — Trust theater: "We use end-to-end encryption and fully comply with GDPR standards. No data is stored on our servers. Please stay on this page until the transfer is complete." This overcomes any remaining security hesitation and keeps the victim on the page while the card data is exfiltrated. The GDPR compliance claim is fraudulent — the platform has no legal basis to process or retain payment data.

The full card harvest form collects: 16-digit card number, expiry month/year, CVV, cardholder name — all data required for CNP (card-not-present) fraud, international wire transfers, and card cloning.

Account restriction lure — Allegro Lokalnie branding Payment method selection — Visa Mastercard PayPal Google Pay
Card harvesting form — card number CVV expiry cardholder Emma support chat — push payment fraud lure
GDPR compliance theater — trust manipulation
# Full kill chain — documented via live test session (2026-08-17, Belgian Orange incognito Chrome) ## STEP 1 — Card data collection Agent: "Emma from Customer Support" Lure: "The buyer has already completed the payment." "To receive the funds, please provide your card details." ← PUSH PAYMENT FRAUD — victim believes they are receiving money, not surrendering card Fields taken: Card Number (PAN) · Month/Year · CVV · Cardholder Name ← Complete CNP fraud dataset on first submit ## STEP 2 — Balance interrogation Attention dialog: "The bank requested additional bank card information to verify card ownership." Chat message: "Please enter the exact current balance." "If the balance does not match, your card may be temporarily blocked." ← Threat forces compliance. Balance reveals how much victim has — calibrates theft amount. Field added: Card Balance (exact amount, e.g. 999.99) ## STEP 3 — Minimum balance demand + theft trigger Chat response: "Sorry, but you need to enter a card with a balance at least INR 20'000" "or you can top up your actual card balance with this amount." "Your bank will run a test transaction, which will verify you in our system." ← "Test transaction" = real theft of INR 20,000 (~€220) ← "Top up first" = instruct victim to load funds before stealing them ## CURRENCY LEAK — platform origin intelligence Demanded currency: INR (Indian Rupee) ← NOT Polish Złoty (PLN) ← Platform was originally built for the Indian market. Operators failed to localize this message for Poland. Indicates operator base or kit origin is India.
Attention dialog — bank requests additional card info Chat asks for exact card balance
Card balance field added to form Expect — bank processing screen
INR 20000 minimum balance demand — currency leak
This is not phishing — it is a multi-step push-payment fraud operation. The platform collects full card data (step 1), interrogates the victim's balance to calibrate the theft amount (step 2), then demands a minimum balance of INR 20,000 and triggers a "test transaction" — the actual charge (step 3). The INR currency demand is an operational error that reveals the kit was originally built for India and adapted for Poland, giving investigative agencies a geographic lead on the operator base.
Reporting Actions

Cloudflare Trust & Safetyabuse@cloudflare.com — highest priority. Platform hosted on Cloudflare Pages, protected by Cloudflare Bot Management. Single takedown removes both host and shield.

NameSilo Abuseabuse@namesilo.com — basicmodoralo.com registrar. Domain suspension removes the entire platform.

Global Domain Group LLCabuse@globaldomaingroup.com — registrar for phishing entry domains (allegrolokalnie.help and cluster).

CERT Polska (CERT.pl)cert@cert.pl — Polish national CERT. Allegro is Poland's primary e-commerce platform, making this a national-scale incident.

Allegro Security Teamsecurity@allegro.pl — brand abuse and user alert. Allegro can push in-app warnings to 21M users and file direct platform abuse claims with Cloudflare.

EC3 / Europolec3@europol.europa.eu — cross-border financial fraud (Poland, EU).

Indicators of Compromise
# Platform basicmodoralo.com ← PhaaS platform · NameSilo · 2026-08-04 mx.basicmodoralo.com ← geographic traffic router go.basicmodoralo.com ← redirect shortener track.basicmodoralo.com ← victim tracking admin.basicmodoralo.com ← operator admin panel panel.basicmodoralo.com ← campaign management api.basicmodoralo.com ← backend API # Hosting IPs (Cloudflare Pages — origin masked) 188.114.96.2 ← Cloudflare Pages AS13335 188.114.97.2 ← Cloudflare Pages AS13335 # Entry domains (sample — 3,309 total) allegrolokalnie.help ← confirmed redirect to platform · 2026-08-15 allegrolokalnie.pln738.lol ← phishing domain allegro.52399129gg.casa ← phishing domain allegro.320029h8h8.forum ← oldest sample · registered 2026-07-15 allegro.1509smart94301.study ← phishing domain # Campaign URLs basicmodoralo.com/mx/n/1855468643 ← non-EU route basicmodoralo.com/n/438227451786911 ← Belgian route · CONFIRMED LIVE # Registrars NameSilo LLC ← platform registrar Global Domain Group LLC ← phishing domain registrar
Evidence — basicmodoralo.com Infrastructure Map
basicmodoralo.com infrastructure and domain pattern analysis
Takedown Evidence — NameSilo Abuse Response #468369
NameSilo ClientHold confirmation email and WHOIS verification
NameSilo ticket #468369 · Subject: "Phishing Report: #468369 [basicmodoralo.com]" · Confirmed ClientHold applied 2026-08-17 19:45 UTC
Live Web Capture — Domain Dead Post-Seizure
Playwright capture confirming ERR_NAME_NOT_RESOLVED after ClientHold
Playwright headless capture post-ClientHold · basicmodoralo.com → ERR_NAME_NOT_RESOLVED · Domain completely offline
Live Infrastructure Status
Status note: Domain is on ClientHold — all IOCs expected to return DOWN (HTTP 0, no DNS). This is a confirmed registrar seizure, not a temporary connectivity issue.
Loading status…
Previous: Case 009 — bpost-secure.com Next: Case 011 — support-postal.com
SevinOS BLE Radar