mail[.]node[.]legionweb[.]co
Análisis de phishing y seguridad de mail.node.legionweb.co
“Roundcube Webmail :: Welcome to Roundcube Webmail”
mail.node.legionweb.co — Último activo conocido (HTTP 302). Tipo de estafa: Credential Phishing. Resumen de las pruebas: VT 7/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); URLQuery 1 alert; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 86/100. Registrador: PlanetHoster.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
PhishDestroy first observed mail.node.legionweb.co on Feb 10, 2026. The current evidence record is rated high at 86/100. 4 independent sources recorded positive findings: VirusTotal, MetaMask, SEAL, and URLQuery.
VirusTotal recorded 7 detections among 91 engines: ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Gridinsoft on Jul 27, 2026 at 02:20 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 14:20 UTC. URLQuery recorded 1 threat-system alert on Feb 10, 2026 at 16:32 UTC. Google Safe Browsing returned no flag on Jun 26, 2026 at 23:11 UTC. URLScan completed without a malicious verdict (score 0) on Feb 10, 2026 at 15:15 UTC.
HTTP 302 was recorded on Aug 7, 2026 at 10:19 UTC. Registration records for the registrable domain legionweb.co list PlanetHoster Inc. as the registrar. At collection time, the domain resolved to 199.16.129.199 on AS53589 (PlanetHoster). The stored server header is LiteSpeed. Captured page title: “Roundcube Webmail :: Welcome to Roundcube Webmail”. PhishDestroy classified the observed content as Credential Phishing. DOM analysis completed on Jul 10, 2026 at 18:20 UTC; stored DOM score 85/100. IoC extraction completed on Jul 29, 2026 at 02:37 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. TLS metadata lists Let's Encrypt as the certificate issuer with validity through May 11, 2026; checked Mar 15, 2026 at 05:41 UTC.
A stored capture reference is available for visual review. No target brand has been confirmed from stored page content; hostname wording alone is not treated as brand evidence.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | mail.node.legionweb.co |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 7 identified
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of mail.node.legionweb.co · checked Jun 27, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.