Security Scan Report: bankofamerica-uscom.vercel.app

Site favicon
Submitted: Sep 28, 2026, 12:45:25 AMCompleted: Sep 28, 2026, 12:46:57 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 87%

8
Risk Score

Fake Bank of America site on a vercel.app lookalike subdomain, copying the bank's branding and content and flagged for phishing; do not enter any credentials or personal data.

Risk Factors (5)
Brand impersonation of Bank of America on a mismatched, non-official domain
Hyphenated lookalike hostname ('bankofamerica-uscom') designed to resemble the real bank domain
Single-source threat-intel phishing report on the primary domain
Free/shared hosting subdomain with no attributable age or reputation
IDS alerts for commonly actor-abused cloud hosting service
Domain age information unavailable

Details

Page Title

Bank of America

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'bankofamerica-uscom.vercel.app' is registered, featuring subdomain 'bankofamerica-uscom'. Its registrable label 'vercel' stretches across 6 characters containing two vowels alongside four consonants. Splitting it apart reveals 2 words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bankofamerica-uscom.vercel.app/help

Page Load Overview

9.87s
Total Load Time
490 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2,756 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking76% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
76%
government public service
55%
healthcare medical
51%
technology software
36%
adult content
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
864.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
5142.251.110.95Google · CDNUnited States
AS15169Google LLC
5142.250.154.94Google · CDNUnited States
AS15169Google LLC
5216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
564.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
5142.251.13.95Google · CDNUnited States
AS15169Google LLC
5142.251.13.94Google · CDNUnited States
AS15169Google LLC
387--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16033A7152640CB3DED574EADF3B87F38108D858AD21AE9BAE17D40660243C7E9B32BD4

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:4rueOxe13IWI0ls5FhvFN/R7YfAA7YkYJY9PuYX6i1D:OIwHR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:50754:gwPYJEFECAAVAEwbMYO5oscAAj2gAKCQlHVCQUNyIxzE5DAEACoAmGEPzCrYTFBzRoQwIIOxwIZOskmSmAAAOgIaMmEOM0WN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff000000ffffffff
Perceptual Hash:9d0af5e3f68b08c8
Difference Hash:6ad4f1790052525a
Wavelet Hash:8b000000ffffabfe
Color Hash:#a479d2

Scan History

Scan history not available

Unable to load historical scan data