Security Scan Report: www.securebankofamerica.vercel.app

Redirected to:
https://securebankofamerica.vercel.app/
Submitted: Sep 15, 2026, 12:45:03 AMCompleted: Sep 15, 2026, 12:45:31 AMpubliccompleted

This website contacted 6 IPs in 1 country across 3 domains to perform 71 HTTP transactions. The main domain is securebankofamerica.vercel.app and was registered 27 years ago.

Submitted URL: http://www.securebankofamerica.vercel.app/

Effective URL:

https://securebankofamerica.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed Bank of America credential-phishing clone hosted on a vercel.app subdomain, with a working login form harvesting User ID and passcode and two HIGH-severity phishing IDS alerts naming it specifically.

Risk Factors (5)
Impersonation of Bank of America on a non-official domain (securebankofamerica.vercel.app)
Login form collecting User ID and Password/passcode credentials
HIGH-severity IDS alerts for Bank of America cloned phishing landing pages
Free shared-hosting subdomain with unverifiable, potentially brand-new creation date
Cross-origin credential form submission to bankofamerica.com from an unrelated host
Domain age information unavailable

Details

Page Title

Bank of America | Online Banking | Log In | User ID

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'www.securebankofamerica.vercel.app' is registered with subdomain 'www.securebankofamerica'. The second-level label 'vercel' is 6 characters long with two vowels and four consonants. It segments into 2 words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://www.securebankofamerica.vercel.app/

Page Load Overview

7.65s
Total Load Time
50 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:7,920 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking60% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
60%
technology software
52%
government public service
47%
documentation technical
38%
adult content
38%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
16216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1164.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
11100.29.168.163Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
11216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1164.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
716--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T159319488D9E8308540830FC0B4E3F7619526027A6149CCC4F5BC59F99BC7F9261BCB66

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:lmICsAMtvXaIse/YG7AMZEAMUVEAMc6AMrfNQ8bClv:1CeBTseZ7AM2AMUVEAMc6AMjNQ8bClv

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1661:AMACIMAIQAAAAAgAwAAAAAAAAAC4AgABABAAIgAAIAAAACACQIAAAAIMAGQgACAAQIAAAAAABACABQCAAYIAAAAQAIAAEQAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0f3f3f3f7f1f1f0f
Perceptual Hash:8155103ef93c3f39
Difference Hash:f8c0e0e0c0e0f0d8
Wavelet Hash:063e3e1e3e1e1e06
Color Hash:#5354ac

Other Hashes

Crop Resistant:f8c0e0e0c0e0f0d8

Scan History

Scan history not available

Unable to load historical scan data