app[.]leigion[.]cc
Zusammenfassung der Beweislage
Analysis of app.leigion.cc as of 24 July 2026 indicates that the domain is currently offline, returning HTTP 403 responses for all requests. The zone is served by Cloudflare DNS, using the nameservers daniella.ns.cloudflare.com and santino.ns.cloudflare.com, and the web server is reachable through the Cloudflare edge IP 104.21.74.170, AS13335, located in the United States. The TLS certificate presented is issued by Google Trust Services under the WE1 designation, confirming that the site can present a valid HTTPS connection despite its inactive state. Registration data show the domain was created on 16 December 2025 and was registered through NiceNIC International Group Co., Limited, which aligns with the recent surge of abuse observed for newly minted domains.
Security telemetry reports 16 of 95 VirusTotal scanners flagging the domain, and Google Safe Browsing classifies it as a social‑engineering threat. Independent blocklist providers PhishDestroy and ScamSniffer have already listed the domain, and it appears on two additional public blocklists. The available intelligence does not include a harvested page title, content snapshot, or explicit phishing kit attribution, leaving the exact lure and credential‑collection mechanism unconfirmed.
Defenders should immediately block DNS resolution and HTTP traffic to app.leigion.cc at perimeter devices, add the IP address 104.21.74.170 to any outbound filtering rules, and incorporate the domain into URL‑filtering and threat‑intelligence feeds. Monitoring for newly registered domains that resolve to the same Cloudflare edge IPs or share the same nameserver pair is advisable, as adversaries often recycle this infrastructure. Because the TLS certificate is valid, reliance on certificate inspection alone is insufficient; continuous feed updates from VirusTotal, Google Safe Browsing, and blocklist sources remain essential for timely detection.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Gespeicherte Ergebnisnachweise
Ergebnis und Takedown-Zuordnung
- Ergebnis
blocked- Verfügbarkeit
provider_blocked- Ursache
cloudflare_antiphishing- Akteur
- Cloudflare
- Mechanismus
phishing_interstitial- Konfidenz
- 95%
- Erste Beobachtung
- Letzte Beobachtung
Beweis-SHA-256 34a534273429
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Nicht erreichbar → Erreichbar
-
Verfügbarkeit
Erster gespeicherter Wert: Unbekannt
993d00c35140 -
Verfügbarkeit
Unbekannt → Blockiert
d949728e02c1 -
Verfügbarkeit
Blockiert → Unbekannt
372ff66a90d4 -
Verfügbarkeit
Unbekannt → Blockiert
db2ba451eb6a -
Verfügbarkeit
Blockiert → Unbekannt
7cebcfd4071c -
Verfügbarkeit
Unbekannt → Blockiert
126606308322
Alle anzeigen (6)
-
Verfügbarkeit
Blockiert → Unbekannt
ca255b61650a -
Verfügbarkeit
Unbekannt → Blockiert
42c717440764 -
Verfügbarkeit
Blockiert → Unbekannt
d8f7d37d7f95 -
Verfügbarkeit
Unbekannt → Blockiert
22fd6d24b19a -
Verfügbarkeit
Blockiert → Unbekannt
afa49a2b04dd -
Verfügbarkeit
Unbekannt → Blockiert
34a534273429
Community-Meldungen
Von 1 Community-Mitglied gemeldet; erstmals gesehen am 20.12.2025
- Gespeicherte Meldungen
- 1
- Eindeutige gemeldete URLs
- 1
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of app.leigion.cc · checked Apr 23, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt