Security Scan Report: unionchequers.top

Submitted: Feb 21, 2026, 2:50:15 PMCompleted: Feb 21, 2026, 2:51:44 PMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 3 countries across 17 domains to perform 45 HTTP transactions. The main domain is unionchequers.top and was registered NaN years ago.

Submitted URL: https://unionchequers.top/themes/nwcu-harlo/assets/css/fonts/slickd41d.html?

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Impersonates Northwest Community Credit Union on an unranked domain; likely phishing.

Risk Factors
Brand impersonation on a non‑official, unranked domain
Eval() usage indicating suspicious dynamic code
Abnormal HTTP header detected by IDS
Presence of a login‑style page without legitimate domain association
Domain age information unavailable

Details

Page Title

| NWCU

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

government public service

(51%)

Domain Information

Domain 'unionchequers.top' uses the .top top-level domain with no subdomain. Count 13 characters in 'unionchequers' holding 6 vowels versus 7 consonants. Breaking it apart gives three words: union, cheque, rs. The median word length lands at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://unionchequers.top/themes/nwcu-harlo/assets/css/fonts/slickd41d.html?

Page Load Overview

4.06s
Total Load Time
45
HTTP Requests
17
Domains
514 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:2,160 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service51% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

government public service
51%
finance banking
50%
news media journalism
44%
real estate property
37%
documentation technical
28%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15199.60.103.228United States
AS209242Cloudflare London, LLC
2142.251.36.102United States
AS15169Google LLC
2216.58.206.68United States
AS15169Google LLC
2216.58.206.42United States
AS15169Google LLC
2172.67.221.70United States
AS13335Cloudflare, Inc.
2142.251.141.131United States
AS15169Google LLC
235.210.130.15Brussels, Brussels Capital, Belgium
AS15169Google LLC
2142.251.141.72United States
AS15169Google LLC
223.45.108.190Frankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
2216.239.32.36United States
AS15169Google LLC
4516--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T198B2C52346F1203B0113D6D4A671B36CFE83124BEE4688A1F1FD479A6F92ED69C17A1C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:2LNqdCvVsrtEEHs2JiREprZ7ymSC1gF5ew5AIFg0EE2KlcZP:s8FHsjSrQmwgecZP

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:25191:Likycg2FAaYBaEGAIbR4QSSCkJAAsgZBkAAh0BqIgdAKKLlN+RQGCCHGRIjkaJBHUIOKEIgZilhSZPkOKgdMAsCKRAJoc4Ri

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f7f7f7f7f7f3f3f
Perceptual Hash:80d50f0e070fff0f
Difference Hash:e080c0c0c0c0c0c0
Wavelet Hash:0e4e4e4e4e0e0e0e
Color Hash:#c587a0

Other Hashes

Crop Resistant:e080c0c0c0c0c0c0

Scan History

Scan history not available

Unable to load historical scan data