api.stoffwechsel-revolution.de - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned api.stoffwechsel-revolution.de and returned a suspicious verdict (score 33), categorised as phishing. The page resolved to 103.133.1.2 on Laravel in DE. 5 domains and 2 IPs were contacted, over 7 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 33) · Confidence 39%
- Scanned URL:
https://api.stoffwechsel-revolution.de/ - Domain: api.stoffwechsel-revolution.de · IP: 103.133.1.2 · AS209242 · DE
- Server: cloudflare
- Page title: Stoffwechsel-Revolution
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 17 23: · subject CN=api.stoffwechsel-revolution.de
- HTTP requests captured: 7 · cookies set: 4 · outgoing links: 3
- Scan tier: standard · observed 2026-08-21 12:46:16 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Domain impersonates revolut (combosquat)
- Certificate issued < 48h ago
Detected technologies
- Cloudflare
Contacted infrastructure
- 103.180.114.1 - AS200325 BUNNYWAY, informacijske storitve d.o.o (Australia)
Observed indicators
- api.stoffwechsel-revolution.de
- fonts.bunny.net
- laravel.com
- laracasts.com
- cloud.laravel.com
- 103.133.1.2
- 103.180.114.1
- https://api.stoffwechsel-revolution.de/
- https://fonts.bunny.net/
- https://fonts.bunny.net/css?family=instrument-sans:400,500,600
- https://laravel.com/docs
- https://laracasts.com/
- https://cloud.laravel.com/
- https://api.stoffwechsel-revolution.de/cdn-cgi/challenge-platform/scripts/jsd/main.js
Questions about api.stoffwechsel-revolution.de
- Is api.stoffwechsel-revolution.de safe?
- No. MalwareAnalyzer scanned api.stoffwechsel-revolution.de on 21 Aug 2026 and returned a suspicious verdict with a score of 33 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was api.stoffwechsel-revolution.de checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of api.stoffwechsel-revolution.de
Scanned on MalwareAnalyzer by Cyble · Open interactive scan