Security Scan Report: northucrunion.com

Submitted: Apr 17, 2026, 11:11:56 AMCompleted: Apr 17, 2026, 11:13:08 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 38 HTTP transactions. The main domain is northucrunion.com and was registered NaN years ago.

Submitted URL: https://northucrunion.com/login.php

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Phishing site impersonating Northfield Credit Union to harvest user credentials.

Risk Factors
Unranked, newly registered domain
Brand impersonation of a financial institution
Credential login form on a suspicious domain
Lack of any legitimate informational or service content
Absence of Indicators of Compromise may indicate a clean phishing kit
Domain age information unavailable

Details

Page Title

Northfield Credit Union - Login

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(63%)

Domain Information

The domain name 'northucrunion.com' uses the commercial generic top-level domain (.com). The second-level label 'northucrunion' is 13 characters long split between 5 vowels and eight consonants. Segmentation suggests four words: north, u, cr, union. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://northucrunion.com/login.php

Page Load Overview

2.00s
Total Load Time
38
HTTP Requests
3
Domains
250 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:125 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking63% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
63%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
14192.178.183.94United States
AS15169Google LLC
12142.250.186.74United States
AS15169Google LLC
1291.204.209.2United Kingdom
AS52148Enix Ltd
383--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E8F286534C81254BF52B8E699AD8F90C16E8D207FD330D5DB66CE0148F97FCE14AA35A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:KTagNPIPw6g1Zv8KZe2TheUB+Ye/IPpIuyEY:KTaC6gD8VUB+Ye/WvyEY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:35459:kzYQIg+gCBhEMEsSIEAEg9wAgAZGAPalIBIJgWBKROJ4MUCUwTDGOUoFQCLeEBRiWmT0pQ+kCiBhBAQWABQQiEC2BgAQDES4

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7ffe7e7ffff
Perceptual Hash:b399cc669999668c
Difference Hash:00000c100c4d000c
Wavelet Hash:f0f0c0c0c0c0fcfc
Color Hash:#c3e06c

Other Hashes

Crop Resistant:00000c100c4d000c

Scan History

Scan history not available

Unable to load historical scan data