Security Scan Report: citiretailservices.citibankonline.com

Redirected to: https://citiretailservices.citibankonline.com/RSauth/signon?pageName=signon&siteId=PLCN_COSTCO&langId=en_US

Submitted: Oct 30, 2025, 1:35:50 PMCompleted: Oct 30, 2025, 1:37:33 PMpubliccompleted
Loading additional data...

Summary

This website contacted 26 IPs in 2 countries across 7 domains to perform 48 HTTP transactions. The main domain is citiretailservices.citibankonline.com and was registered NaN years ago.

Submitted URL: https://citiretailservices.citibankonline.com/RSnextgen/svc/launch/index.action?siteId=PLCN_COSTCO

Effective URL: https://citiretailservices.citibankonline.com/RSauth/signon?pageName=signon&siteId=PLCN_COSTCO&langId=en_USRedirected

AI Security Verdict

AI analysis unavailable for this scan

Details

Page Title

Citi Cards: Log In or Apply

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

other

(48%)

Domain Information

The domain name 'citiretailservices.citibankonline.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'citiretailservices'. The registrable portion 'citibankonline' spans 14 characters with six vowels and eight consonants. Tokenizing the label suggests 3 words: citi, bank, online. Median word length is four characters. 'citi' most often appears in Romanian. Secondary signals appear in Italian and Catalan.

Screenshot

Security scan screenshot of https://citiretailservices.citibankonline.com/RSnextgen/svc/launch/index.action?siteId=PLCN_COSTCO

Page Load Overview

32.59s
Total Load Time
48
HTTP Requests
7
Domains
1.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:12,006 chars
Detector Agreement:100%

Website Classification

Primary Category

other48% confidence
Type: spa
Method: ml+structural

All Detected Categories

other
48%
suspicious phishing
42%
legitimate website
36%
malicious
32%
e-commerce
27%

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2323.39.72.56United States
AS6762TELECOM ITALIA SPARKLE S.p.A.
165.9.66.103United States
AS16509AMAZON-02
1188.114.97.3United States
AS13335CLOUDFLARENET
1142.250.185.98United States
AS15169GOOGLE
165.9.66.24United States
AS16509AMAZON-02
165.9.66.72United States
AS16509AMAZON-02
165.9.66.34United States
AS16509AMAZON-02
135.190.22.40United States
AS396982GOOGLE-CLOUD-PLATFORM
1142.250.185.142United States
AS15169GOOGLE
13.124.119.57Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
4826--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T196830B45F3AD3472420312B1F19B255A9C3EC2EED59D2890BD5CC0B82FE2D59912F7AE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:Gg9sDF631e2O5+ShvYhlFC5oe460JzL0ghdG6HgaBY+lLiHwEhuGJV4b1:GCsDF/vwlc5oeQVKqihuGJV4x

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:86981:xSNwQNAPAAMAgQEMeQiRpFypjCRgC4JSQYEYU8wAwoQEIZFRqgMEEAkVAJNxBUiI5pAugAiDG5hFqIgAOwQWIPIGEPYSIlyx

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffffffffff
Perceptual Hash:870f0f0f0f0f0f0f
Difference Hash:c000000000000000
Wavelet Hash:00ffffff00000000
Color Hash:#40bfae

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data