midfloridacu[.]at
“MIDFLORIDA Credit Union — Official MIDFLORIDA Credit Union Site”
midfloridacu.at — 隐形 · 可达. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); Google Safe Browsing flagged; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 100/100. 注册商: Hosting concepts.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, midfloridacu.at, is actively engaged in credential harvesting by impersonating the legitimate online banking portal of MidFlorida Credit Union. Analysis indicates the site is designed to mimic the authentic login interface, tricking users into submitting sensitive financial credentials, including usernames, passwords, and multifactor authentication codes. The threat extends to potential account takeover, unauthorized fund transfers, and identity theft, given the targeted nature of financial phishing campaigns. The domain is classified under the SOCIAL_ENGINEERING category, confirming its intent to deceive users through fraudulent representations of trust. Evidence supporting the malicious classification includes detection by 13 out of 95 security vendors on VirusTotal, with Google Safe Browsing explicitly flagging it for SOCIAL_ENGINEERING. The domain was registered through Hosting Concepts B.V. via Registrar.eu, a provider frequently associated with bulletproof hosting and low-reputation registrations. Infrastructure analysis reveals the domain resolves to the IP address 107.189.26.168, an address previously linked to multiple phishing and malware distribution campaigns. The SSL certificate is issued by Let’s Encrypt, a common tactic to lend superficial legitimacy while avoiding the scrutiny of paid certificates. Additionally, AlienVault OTX records the domain in two distinct threat intelligence pulses, further corroborating its association with malicious activity. Users who have visited midfloridacu.at or entered credentials on the site should immediately take corrective action. First, revoke any active sessions on the legitimate MidFlorida Credit Union platform and change all associated passwords using a secure, non-compromised device. Enable multifactor authentication if not already active, and monitor account statements for unauthorized transactions. If financial data or personal information was submitted, contact the financial institution directly to report potential fraud and request account monitoring. Network administrators should block the domain and its resolving IP (107.189.26.168) at the perimeter to prevent further exposure. Users are advised to verify the legitimacy of any financial login portal by cross-referencing the URL with the official domain provided by the institution and looking for HTTPS indicators with a valid, organization-issued certificate.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 1 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of midfloridacu.at · checked Jul 9, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。