www.bankofamerica.com - URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned www.bankofamerica.com and returned a unknown verdict (score 8), categorised as credential-harvest. The page resolved to 23.33.238.101 on Akamai Technologies, Inc. in AU. The domain was registered 10094 days ago through CSC Corporate Domains, Inc.. 10 domains and 2 IPs were contacted, over 2 HTTP requests. 2 malware samples communicate with this URL (Vobfus). The request followed 1 redirect before landing. This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 8) · Confidence 55%
- Scanned URL:
https://bankofamerica.com/ - Domain: www.bankofamerica.com · IP: 23.33.238.101 · AS20940 · AU
- Page title: Bank of America - Banking, Credit Cards, Loans and Merrill Investing
- HTTP status: 200 · text/html
- Registrar: CSC Corporate Domains, Inc. · domain age 10094 days · created 1998-12-28
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert EV RSA CA G2 · valid to Feb 7 23: · subject jurisdictionC=US, jurisdictionST=Delaware, businessCategory=Private Organization, serialNumber=2927442, C=US, ST=North Carolina, L=Charlotte, O=Bank of America Corporation, CN=www.bankofamerica.com
- Evidenced operator: Bank of America Corporation
- HTTP requests captured: 2
- Scan tier: fast · observed 2026-08-17 05:15:30 UTC
Redirect chain
https://bankofamerica.com/https://www.bankofamerica.com/
Malware communicating with this URL (2)
These samples were observed contacting or being served from www.bankofamerica.com. Each links to its full analysis.
- Vobfus - referenced ·
552cd8cf54d0fca022efea8e051056db· first seen 2026-08-17 - Vobfus - referenced ·
9bae68e13c60e8908b606ff059c71758· first seen 2026-08-15
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 23.33.238.101 - AS20940 Akamai Technologies, Inc. (Australia)
- 3.173.23.90 - AS16509 Amazon.com, Inc. (United States)
Observed indicators
- www.bankofamerica.com
- www2.bac-assets.com
- itunes.apple.com
- play.google.com
- promo.bankofamerica.com
- www.merrilledge.com
- secure.bankofamerica.com
- bettermoneyhabits.bankofamerica.com
- promotions.bankofamerica.com
- locators.bankofamerica.com
- 23.33.238.101
- 3.173.23.90
- https://www.bankofamerica.com/
- https://www.bankofamerica.com/es/
- https://www.bankofamerica.com/homepage/spa-assets/images/assets-images-global-favicon-apple-touch-icon-CSX889b28c.png
- https://www.bankofamerica.com/homepage/spa-assets/images/assets-images-global-favicon-favicon-32x32-CSX704d6b21.png
- https://www.bankofamerica.com/homepage/spa-assets/images/assets-images-global-favicon-favicon-16x16-CSXaaa5ca4e.png
- https://www.bankofamerica.com/homepage/spa-assets/images/assets-images-global-favicon-android-chrome-192x192-CSXafb7d716.png
- https://www.bankofamerica.com/homepage/spa-assets/images/assets-images-global-favicon-safari-pinned-tab-CSX1aebeef6.svg
- https://www.bankofamerica.com/homepage/spa-assets/images/assets-images-global-favicon-favicon-CSX8d65d6e4.ico
Other scans of www.bankofamerica.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 20 Aug 2026 - unknown
- 15 Aug 2026 - unknown
Questions about www.bankofamerica.com
- Is www.bankofamerica.com safe?
- The scan of www.bankofamerica.com on 17 Aug 2026 reached no verdict either way (score 8). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.bankofamerica.com?
- 2 analysed samples communicate with this URL, including Vobfus.
- How was www.bankofamerica.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.bankofamerica.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan