dfcufinancialonline[.]co[.]com
“www.www.dfcufinancialonline.co.com”
dfcufinancialonline.co.com — Непроверенный. Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 2/91 (alphaMountain.ai, Gridinsoft); PhishDestroy score 71/100. Регистратор: Moniker Online Services.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, dfcufinancialonline.co.com, is actively flagged as a credential phishing site targeting financial sector credentials. As of July 12, 2026, it remains operational and resolves to IP 104.21.14.23, hosted on Cloudflare infrastructure (AS13335). Analysis indicates a 301 HTTP redirect, suggesting the domain may serve as an intermediate hop rather than the final phishing page. The page title, 'www.www.dfcufinancialonline.co.com,' appears malformed, which could indicate rushed deployment or obfuscation tactics. Only 2 of 91 security vendors on VirusTotal have detected this domain, though this does not confirm benign status given the low detection rate for newly registered phishing domains. The domain is registered through Moniker Online Services LLC and uses nameservers ns1.nic.co.com through ns4.nic.co.com, a pattern observed in other phishing campaigns leveraging the .co.com subdomain namespace. Infrastructure analysis reveals the use of a Let's Encrypt SSL certificate (E7), which is common among both legitimate and malicious sites due to its free availability. The domain appears on one security blocklist, specifically PhishDestroy, aligning with its classification as a high-risk credential phishing threat. Defenders should treat this domain as actively malicious and prioritize blocking it at DNS, proxy, and endpoint layers. Given the 301 redirect, monitoring for downstream domains or IPs in the redirect chain is recommended. No specific brand impersonation details are confirmed beyond the domain name itself, and the exact content of the phishing page remains unanalyzed. Further investigation into associated IPs, SSL certificate patterns, and redirect targets may reveal additional indicators of compromise.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание