Security Scan Report: access.amexgbt.com

Redirected to:
https://access.amexgbt.com/app/amexgbtb2b_globalportal_1/exk1hwxyqysuf...
Site favicon
Submitted: Jun 30, 2026, 10:32:04 PMCompleted: Jun 30, 2026, 10:33:15 PMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 5 domains to perform 2 HTTP transactions. The main domain is access.amexgbt.com and was registered NaN years ago.

Submitted URL: https://access.amexgbt.com

Effective URL: https://access.amexgbt.com/app/amexgbtb2b_globalportal_1/exk1hwxyqysufHteO0h8/sso/samlRedirected

The Cisco Umbrella rank of the primary domain is #84,444 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 78%

5
Risk Score

Site appears to be a legitimate American Express GBT sign‑in portal, but the heavily obfuscated JavaScript warrants caution.

Risk Factors
Heavy JavaScript obfuscation (CRITICAL score)
Multiple eval() calls and dynamic code execution
Cross‑origin network request to external domain
Safety Factors
Domain age >12 years, well‑established reputation
Cisco Umbrella ranking within top 100 K
No password or payment fields on the page
No Indicators of Compromise or malware signatures
Brand matches official American Express GBT domain
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 5
Domain age information unavailable

Details

Page Title

American Express GBT - Sign In

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(50%)

Domain Information

You're looking at domain 'access.amexgbt.com' on the commercial generic top-level domain (.com) and includes subdomain 'access'. Its registrable label 'amexgbt' stretches across 7 characters holding two vowels versus 5 consonants. Breaking it apart gives three words: amex, gb, t. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://access.amexgbt.com

Page Load Overview

3.48s
Total Load Time
40
HTTP Requests
10
Domains
1.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,423 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software50% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
50%
corporate business
44%
documentation technical
40%
government public service
34%
travel tourism
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
818.245.86.4Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
8194.36.55.5United Kingdom
AS209242Cloudflare London, LLC
865.8.131.81Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
899.83.239.254Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
8194.36.55.251United Kingdom
AS209242Cloudflare London, LLC
405--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14CC36C1C21B0243782632068E2EFB5553624D1478546ED84BA7E679C8FCBC639AF37ED

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:ibBr8rab6r8r0qlcOf2ZZP3zUiysX3JYadaQGKgwKc:ib+rab9r0qCOf2ZZP3zUiysX3JtdaegS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:125967:FAhApsDUUQgoAgAFAzgE4QAwBgoR0HAxKotiKFOcEKsiUAGIEAiGSQxgC1EZIIgmzQFZMKXqtDkQgAwAeYMQUCQCCIRwKI4T

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffbf3c3f070703ff
Perceptual Hash:a3dccc23cc2c33dc
Difference Hash:6a7974e74f4fcf37
Wavelet Hash:3f1f1c13070303ff
Color Hash:#59d22d

Scan History

Scan history not available

Unable to load historical scan data