Security Scan Report: www.thecitizensbank.net

Site favicon
Submitted: Dec 10, 2025, 4:54:23 PMCompleted: Dec 10, 2025, 4:55:59 PMpubliccompleted
Loading additional data...

Summary

This website contacted 140 IPs in 5 countries across 34 domains to perform 187 HTTP transactions. The main domain is thecitizensbank.net and was registered NaN years ago.

Submitted URL: https://www.thecitizensbank.net/

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

Likely phishing site impersonating Citizens Bank; do not enter credentials.

Risk Factors
Brand impersonation on an unusual, unranked domain
Unranked domain claiming a major financial institution
Presence of a sign‑in interface without visible password field (potential hidden field)
Domain age information unavailable

Details

Page Title

Home | The Citizens Bank

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(27%)

Domain Information

The domain name 'www.thecitizensbank.net' uses the network infrastructure generic top-level domain (.net); it also runs on subdomain 'www'. Its registrable label 'thecitizensbank' stretches across 15 characters split between five vowels and 10 consonants. It segments into 3 words: the, citizens, bank. The median word length lands at 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.thecitizensbank.net/

Page Load Overview

34.74s
Total Load Time
187
HTTP Requests
34
Domains
2.8 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:2,638 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking27% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
27%
corporate
25%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
48104.26.12.87United States
AS13335CLOUDFLARENET
1142.250.185.195United States
AS15169GOOGLE
164.233.166.154United States
AS15169GOOGLE
1216.58.212.130United States
AS15169GOOGLE
118.66.102.53United States
AS16509AMAZON-02
157.144.244.128Frankfurt am Main, Hesse, Germany
AS32934FACEBOOK
1216.58.212.138United States
AS15169GOOGLE
1212.102.56.179Frankfurt am Main, Hesse, Germany
AS60068Datacamp Limited
1104.18.15.11United States
AS13335CLOUDFLARENET
1172.66.163.219United States
AS13335CLOUDFLARENET
187140--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T122B3D85298F5313A409745CAF17AA75AF9C1B203D63360C5F46C83A04BE2D9F6E93E2D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:wFFF2YUNqzaXHUDXAlh7BYg7H47tXILlJQz9BWiww2LbyotyYPXGzp0I/+DU:LYUNqziWgddkQbyAdU0/DU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:117819:BFpHaYLAkESADyAYBjoI8EECjLDBROIiJJ1sAYGwA2wwFxFYENAvgxggADCBIayRIDalBU8FFQgQDpJEgCPMAB8AMQR0kOQL

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0000fffffffb3c
Perceptual Hash:da35cdb4d2ad4a60
Difference Hash:405101a9cd3133e8
Wavelet Hash:ff00007d7f1df118
Color Hash:#2d8186

Other Hashes

Crop Resistant:405101a9cd3133e8

Scan History

Scan history not available

Unable to load historical scan data