Security Scan Report: account.optumbank.com

Redirected to: https://www.healthsafe-id.com/rt/login/cap/en?TARGET=https%3A%2F%2Fwww.healthsafe-id.com%2Frt%2Fsecure%2Fauth%2Fcap%2Fen%3Fresume%3D%2Fas%2FHI8GvF4EQl%2Fresume%2Fas%2Fauthorization.ping%26pfidpadapterid%3DHsidNewUIOidc%26scope%3Dopenid%2520profile%26client_id%3Dbank-cloud-prod%26portal%3Dcap%26spentity%3Dnull%26redirect_uri%3Dhttps%3A%2F%2Faccount.optumbank.com%2Flogin%2Fcallback%26response_type%3Dcode%26redirect%3Dtrue&resume=%2Fas%2FnlqPNUTlXq%2Fresume%2Fas%2Fauthorization.ping&reason=0

Site favicon
Submitted: Jan 17, 2026, 7:53:10 PMCompleted: Jan 17, 2026, 7:54:27 PMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 3 countries across 16 domains to perform 33 HTTP transactions. The main domain is healthsafe-id.com and was registered NaN years ago.

Submitted URL: https://account.optumbank.com

Effective URL: https://www.healthsafe-id.com/rt/login/cap/en?TARGET=https%3A%2F%2Fwww.healthsafe-id.com%2Frt%2Fsecure%2Fauth%2Fcap%2Fen%3Fresume%3D%2Fas%2FHI8GvF4EQl%2Fresume%2Fas%2Fauthorization.ping%26pfidpadapterid%3DHsidNewUIOidc%26scope%3Dopenid%2520profile%26client_id%3Dbank-cloud-prod%26portal%3Dcap%26spentity%3Dnull%26redirect_uri%3Dhttps%3A%2F%2Faccount.optumbank.com%2Flogin%2Fcallback%26response_type%3Dcode%26redirect%3Dtrue&resume=%2Fas%2FnlqPNUTlXq%2Fresume%2Fas%2Fauthorization.ping&reason=0Redirected

The Cisco Umbrella rank of the primary domain is #107,321 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing site impersonating OptumBank login; do not enter credentials.

Risk Factors
Brand impersonation on non‑official domain
Credential harvesting form on suspicious domain
Low Cisco Umbrella ranking for a site claiming a major brand
Excessive redirects (7) before reaching final URL
Domain age information unavailable

Details

Page Title

Secure, convenient sign in. - OptumBank

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

Domain 'account.optumbank.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'account'. The registrable portion 'optumbank' spans 9 characters holding 3 vowels versus 6 consonants. Breaking it apart gives 3 words: op, tum, bank. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://account.optumbank.com

Page Load Overview

6.19s
Total Load Time
95
HTTP Requests
22
Domains
441 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:739 chars
Detector Agreement:75%

Website Classification

Primary Category

unknown0% confidence
Type: spa
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2013.33.220.227New York, New York, United States
AS16509AMAZON-02
554.75.62.54Ireland
565.9.175.110United States
563.140.62.210Unknown
5168.183.45.23United States
520.14.193.193Boydton, Virginia, United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
554.192.35.122Unknown
5168.183.45.29United States
513.35.58.102United States
AS16509AMAZON-02
5104.17.208.240United States
AS13335CLOUDFLARENET
9516--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10862F9361C10543782138ACEB2BAF74DF197D24ECF466841E1F883C967E2EE5992358A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:Wq/v0jrdpp3kkhf+LwIYvpW91TteDRGdDm7tdVPcuh4TAT:l1khf+LPOWhetYm79P/gu

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:14904:rPEijEAsIJoQEji6FoKUgCpgKBAgGDq4EgJRaC2UslAJTEBvHFB0AeACFUMhFEwVBhwi8ljAFHHiFRyQGEg3IQRYdjcEARBQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:9fe7e7ffe7e7c306
Perceptual Hash:b7cb1c621dc89d62
Difference Hash:300c0c104c0c0c3a
Wavelet Hash:9ee6e6eee6e68000
Color Hash:#e08b6c

Other Hashes

Crop Resistant:300c0c104c0c0c3a

Scan History

Scan history not available

Unable to load historical scan data