www.hsbc.com - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.hsbc.com and returned a benign verdict (score 0). The page resolved to 23.33.238.113 on Akamai Technologies, Inc. in AU. 10 domains and 1 IP were contacted, over 4 HTTP requests. 1 malware sample communicates with this URL. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 34%
- Scanned URL:
https://www.hsbc.com/ - Domain: www.hsbc.com · IP: 23.33.238.113 · AS20940 · AU
- Page title: HSBC Group corporate website | HSBC Holdings plc
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert EV RSA CA G2 · valid to Feb 9 23: · subject jurisdictionC=GB, businessCategory=Private Organization, serialNumber=09231974, C=GB, L=London, O=HSBC Group Management Services Limited, CN=www.hsbc.com
- Evidenced operator: HSBC Group Management Services Limited
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-22 15:57:04 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.hsbc.com. Each links to its full analysis.
- 9ee8a200a5626e37c1914939cd0e1b95e46156b6ae3e86a2af706e73a9312ff6 - referenced ·
9ee8a200a5626e37c1914939cd0e1b95· first seen 2026-08-22
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 23.33.238.113 - AS20940 Akamai Technologies, Inc. (Australia)
Observed indicators
- www.hsbc.com
- tags.tiqcdn.com
- www.about.hsbc.com.hk
- www.linkedin.com
- www.instagram.com
- www.facebook.com
- www.youtube.com
- beian.miit.gov.cn
- wap.scjgj.sh.gov.cn
- www.beian.gov.cn
- 23.33.238.113
- https://www.hsbc.com/
- https://www.hsbc.com/assets/basekit.features/favicon/images/favicon.ico
- https://www.hsbc.com/apple-touch-icon.png
- https://www.hsbc.com/apple-touch-icon-precomposed.png
- https://www.hsbc.com/styles/hsbc.css?v=2.85.0.54.0
- https://www.hsbc.com/styles/hsbc.print.css?v=2.85.0.54.0
- https://www.hsbc.com/scripts/hsbc.common.transpiled.js?v=2.85.0.54.0
- https://www.hsbc.com/scripts/hsbc.head.transpiled.js?v=2.85.0.54.0
- https://tags.tiqcdn.com/utag/hsbc/global-common-dotcom/prod/utag.sync.js
Questions about www.hsbc.com
- Is www.hsbc.com safe?
- The scan of www.hsbc.com on 22 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with www.hsbc.com?
- 1 analysed samples communicate with this URL.
- How was www.hsbc.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.hsbc.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan