Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mail[.]node[.]legionweb[.]co
“Roundcube Webmail :: Welcome to Roundcube Webmail”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
The domain mail.node.legionweb.co is identified as a fake login phishing site and is currently offline. This domain was designed to mimic legitimate webmail services, specifically Roundcube Webmail, to deceive users into disclosing their login credentials.
Analysis indicates that mail.node.legionweb.co was flagged by 2 of 95 VirusTotal vendors, suggesting a moderate level of detection among the security community. The domain was registered through PlanetHoster Inc. and resolves to the IP address 199.16.129.199. It was created on February 21, 2026. The domain appears on 3 security blocklists, including MetaMask, SEAL, and PhishDestroy, and has a Gridinsoft trust score of 0/100, indicating a complete lack of trust. The site uses technologies such as RoundCube, PHP, Bootstrap, LiteSpeed, jQuery UI, and jQuery, and supports HTTP/3. The SSL certificate is issued by Let's Encrypt.
Given the current offline status of the domain, organizations and individuals should remain vigilant and ensure that all users are aware of the potential threat. It is recommended to update security policies to block access to this domain and to monitor network traffic for any attempts to access it. Additionally, users should be educated on the signs of phishing attacks and encouraged to verify the authenticity of webmail login pages before entering any credentials.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260210-D01DD2- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Acceptable Use Policy (AUP): The domain mail.node.legionweb.co is being used for phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities and fraud.
Terms of Service (TOS): The fraudulent nature of the services associated with this domain allows for immediate suspension or termination under your TOS, which reserves the right to act against such violations.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030: Prohibits unauthorized access to computers and the use of such access to commit fraud.
Wire Fraud - 18 U.S.C. § 1343: Criminalizes schemes to defraud individuals or entities via electronic communications.
CAN-SPAM Act - 15 U.S.C. § 7701: Regulates commercial email and prohibits deceptive practices in electronic communications.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. Compliance with your AUP and TOS is essential to mitigate risks associated with domain abuse.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | mail.node.legionweb.co |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
Linha do tempo de detecção
-
VirusTotal
2 → 3
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of mail.node.legionweb.co · checked Jun 27, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo