legionccs[.]com
Domain Security & Threat Intelligence Report
The domain is hosted on IP 104.21.94.102 and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, created just 6 days ago. The domain was registered just 6 days ago, highly suspicious for any legitimate business. The domain presents an SSL certificate issued by WE1. This domain is flagged on the PhishDestroy security blocklist.
As of our latest check, legionccs[.]com remains active. PhishDestroy has reported this domain to relevant abuse contacts and continues monitoring for takedown. Users who encounter this domain should avoid entering any credentials or connecting wallets.
Related phishing domains to investigate: Other suspicious domains registered via NICENIC INTERNATIONAL GROUP CO., LIMITED: [unlock-wlfi.xyz](/domain/unlock-wlfi.xyz), [season1-dreamcash.com](/domain/season1-dreamcash.com).
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
porter.ns.cloudflare.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 104.21.94.102
More Domains at NICENIC INTERNATIONAL GROUP CO., LIMITED
About This Report: legionccs.com
This domain security report for legionccs.com is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 1 public blocklists, URLScan.io.
legionccs.com has been flagged by 2 security vendors as of February 28, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive



URLScan Report