Security Scan Report: www.johnsonfinancialgroup.com

Site favicon
Submitted: Jun 21, 2026, 8:16:28 AMCompleted: Jun 21, 2026, 8:18:10 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 9 domains to perform 2 HTTP transactions. The main domain is johnsonfinancialgroup.com and was registered NaN years ago.

Submitted URL: https://www.johnsonfinancialgroup.com/

The Cisco Umbrella rank of the primary domain is #562,172 of the top 1 million websites

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

The site hosts hidden credential forms that submit to an external domain, indicating a confirmed phishing operation.

Risk Factors
Cross‑origin form action to unrelated domain
Hidden password fields
Multiple credential forms on a financial site
Low Cisco Umbrella ranking for a brand‑claiming domain
Domain age information unavailable

Details

Page Title

Personal, Business and Commercial | Banking and Wealth | Johnson Financial Group

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(93%)

Domain Information

You're looking at domain 'www.johnsonfinancialgroup.com' on the commercial generic top-level domain (.com) and includes subdomain 'www'. Count 21 characters in 'johnsonfinancialgroup' holding 8 vowels versus 13 consonants. Word splitting yields three words: johnson, financial, group. Median word length comes out to seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.johnsonfinancialgroup.com/

Page Load Overview

5.88s
Total Load Time
174
HTTP Requests
35
Domains
3.8 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:21,241 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking93% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
93%
technology software
45%
government public service
36%
finance/banking
25%
news/blog
20%

Detected Features

Login Form
Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
22192.0.63.252United States
AS62659Q2 Software, Inc.
193.171.214.12United States
AS16509Amazon.com, Inc.
19142.251.157.119United States
AS15169Google LLC
19104.19.147.8United States
AS13335Cloudflare, Inc.
1974.125.29.95United States
AS15169Google LLC
19150.171.109.194United States
AS8075Microsoft Corporation
19146.75.121.181Frankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
19172.64.153.171United States
AS13335Cloudflare, Inc.
19172.64.149.154United States
AS13335Cloudflare, Inc.
1749--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10C34F711E5F4283711A362C279A17B28BDC19007E209A541BEFC478D5FF2EA79E2B71D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:o/9WkyKjoAMv87w3BnN3iB+ZCVzG325bFYclpN0YvLd3ovqBqc:kxkNSBICVzG2+KxYi3

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:247879:WRMQIcDY3Awy0eRI6TMoTigA6KAEagFkEQCCWAFAwB0IJAFAhpCUGwg1ABjJAAGCoTAY8ohBmaIGCUeQoU0dQCKZkfdiUEwS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff9f9383838383ff
Perceptual Hash:bf0cc073c26b621f
Difference Hash:6937373b7b5b5b4d
Wavelet Hash:bf9f0703010383ff
Color Hash:#a4bf40

Scan History

Scan history not available

Unable to load historical scan data