Security Scan Report: www.homelending.53.com

Redirected to:
https://www.homelending.53.com/#/
Submitted: Apr 26, 2026, 9:14:26 AMCompleted: Apr 26, 2026, 9:15:43 AMpubliccompleted
Loading additional data...

Summary

This website contacted 11 IPs in 2 countries across 11 domains to perform 33 HTTP transactions. The main domain is homelending.53.com and was registered NaN years ago.

Submitted URL: https://www.homelending.53.com/

Effective URL: https://www.homelending.53.com/#/Redirected

The Cisco Umbrella rank of the primary domain is #27,558 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 93%

5
Risk Score

The site impersonates Fifth Third Bank and harvests credentials via a login form on an unrelated domain, confirming a credential phishing scam.

Risk Factors
Brand impersonation
Credential harvesting form
Mismatched domain vs. brand
Use of reputable brand to lure users
Safety Factors
Domain age >30 years (well‑established)
No Indicators of Compromise matches
No JavaScript malware or IDS alerts
External assets are from reputable providers (Google, Adobe, AWS S3)
Established domain (11118 days old) with no strong malicious indicators — risk clamped from 10 to 5
Domain age information unavailable

Details

Page Title

Fifth Third Bank, N.A. | Login

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(57%)

Domain Information

Domain 'www.homelending.53.com' uses the commercial generic top-level domain (.com), featuring subdomain 'www.homelending'. Count 2 characters in '53' split between zero vowels and zero consonants, plus two digits. It segments into one word: 53. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.homelending.53.com/

Page Load Overview

3.95s
Total Load Time
42
HTTP Requests
16
Domains
185 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:374 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking57% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
57%
real estate property
30%
government public service
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12107.22.91.180Germany
354.165.47.40United States
323.52.181.12Frankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
352.217.40.92Unknown
318.66.122.102United States
AS16509Amazon.com, Inc.
3192.178.183.95United States
AS15169Google LLC
3172.65.242.70United States
AS13335Cloudflare, Inc.
3142.251.110.94United States
AS15169Google LLC
33.208.141.91Ashburn, Virginia, United States
AS14618Amazon.com, Inc.
363.32.39.14UnknownUnknown
4211--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F2D3845BAA4039EE49D3CD96D6BFBB3B64348C31920A2A7DB41C233D979FDA14301D25

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:hK3HA2W1ZbK81MH5WBW9O0hOTOYqzD342IUzlyTR:kA2WX2SG9O0ho/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:132080:xCDkEIIglGAAABUpYA0sgqgrIAoQCbCEcRQBACZIgCCyg4CCnEhPdJggIOM4AQwbKCUmSSbhYSxRyyUEQwihsIQiE8EYmA1L

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1f1f1f1f1f1f1f1f
Perceptual Hash:9cf0cc8f3307ccf0
Difference Hash:34b4b47c7cb43434
Wavelet Hash:1f1f03030f1f1f1e
Color Hash:#78862d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data