Here is the whatweb output: ./whatweb https://online.citibank.com https://online.citibank.com [200] X-UA-Compatible[IE=EmulateIE7, IE=EmulateIE7], UncommonHeaders[jid], Cookies[JFPWebAppInfo,JSESSIONID], Title[Citibank Online], Country[UNITED STATES][US]
Looks like something Java-based. It's fun that sometimes software gets so large that they miss a gaping security hole like this.