Security Scan Report: fnm.mcguonline.com

Site favicon
Submitted: Jan 9, 2026, 9:43:47 PMCompleted: Jan 9, 2026, 9:45:44 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 1 HTTP transaction. The main domain is fnm.mcguonline.com and was registered NaN years ago.

Submitted URL: https://fnm.mcguonline.com/account/signup/verify-registration.php

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

High risk phishing site collecting credentials under a fake First National Merchant registration.

Risk Factors
Password fields collected on a recently registered, unranked domain
Brand impersonation on a non‑official domain
Sensitive personal information requested without legitimate purpose
Domain age information unavailable

Details

Page Title

Registration - First National Merchant

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(51%)

Domain Information

You're looking at domain 'fnm.mcguonline.com' on the commercial generic top-level domain (.com), featuring subdomain 'fnm'. The core label 'mcguonline' covers 10 characters holding 4 vowels versus 6 consonants. Word splitting yields three words: mcg, u, online. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://fnm.mcguonline.com/account/signup/verify-registration.php

Page Load Overview

39.68s
Total Load Time
36
HTTP Requests
3
Domains
261 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:3,391 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking51% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
51%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12152.3.138.25Durham, North Carolina, United States
AS13371DUKE-INTERCHANGE
12172.245.155.10Buffalo, New York, United States
AS36352AS-COLOCROSSING
12142.250.186.138United States
363--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C86350125CE0586BA0AB4DDD49E4EA1C59F88303ED36098CF65CC7E14FA3E5ECA73215

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:2Cs7PUPlZv8KZe2Tp7GVJM8/zKLUI2QczYiwA1wkerUPpUj1yEt:2Cn8Yy6wMA1wkerKA1yEt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70706:FIAHnQEMwAhMPwCEEDAEEEGJYoB2AiIThMnAqAECDIQQyaLCAQBkmSRZvUxK7HShShEoQqoLkQgCJSgjGaAAhk4AACACCCiA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0f0f0f0f0f0f0f0f
Perceptual Hash:99f8ce0fe00783d5
Difference Hash:3f3d39be1a5b7a3a
Wavelet Hash:0f0f0f0f0f0f0f0f
Color Hash:#ac5d53

Scan History

Scan history not available

Unable to load historical scan data