bankofamericanonline.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of bankofamericanonline.com
The domain bankofamericanonline.com appears to present itself as an online banking website associated with Bank of America. Its page title, branding, navigation labels, and homepage layout reference consumer banking functions such as mobile banking, transfers, deposits, account management, and card management, suggesting that it is intended to resemble a financial-services portal.
However, the domain name is not the well-known primary domain typically associated with Bank of America, and the page metadata includes a generic development-related description indicating it was "built on Replit." Combined with the very recent registration date, this suggests the site may be an unofficial look-alike rather than a normal corporate banking property. Based on the visible content and branding, the site appears to target users seeking online banking access.
Safety Assessment for bankofamericanonline.com
This website shows multiple high-risk indicators at the time of this scan. The domain was flagged by 20 out of 90 security engines, with many classifying it as phishing or malicious. In addition, it is listed by a major threat database for social-engineering activity. The domain name closely resembles Bank of America branding and may be a look-alike intended to imitate a legitimate banking service, which materially increases the risk of credential theft or other deceptive activity.
Additional context also raises concern. The domain is only 116 days old, has no established traffic ranking, and uses branding that appears designed to match a major financial institution while operating from a different domain. Although the malware scan reported no confirmed infected files, it also produced generic malicious-object indicators on local assets and the domain itself. One mail-reputation blocklist listing was also present, which is a weaker signal on its own but adds to the overall caution when combined with the stronger phishing detections.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-12-01 and is hosted on Google Cloud behind Google Frontend infrastructure, with the server IP resolving to 34.111.179.208 in Kansas City, United States. A valid certificate indicates encrypted transport is available, but it does not by itself verify that the operator is legitimate.
The domain was registered recently through Name.com and is configured with DNSSEC unsigned status, meaning DNS responses do not appear to benefit from DNSSEC validation. From a technical-risk perspective, the combination of recent registration, cloud hosting, generic build metadata, and strong phishing detections across multiple security engines is more concerning than the TLS setup itself.
Share your experience with this website. Was it safe? Did you encounter any issues?