Security Scan Report: bbva-hiring-paperless.appspot.com

Redirected to:
https://bbva-hiring-paperless.appspot.com/crear-cuenta/
Site favicon
Submitted: Sep 15, 2026, 12:45:44 AMCompleted: Sep 15, 2026, 12:46:33 AMpubliccompleted

This website contacted 2 IPs in 1 country across 1 domain to perform 16 HTTP transactions. The main domain is bbva-hiring-paperless.appspot.com and was registered 21 years ago.

Submitted URL: http://bbva-hiring-paperless.appspot.com/crear-cuenta/

Effective URL:

https://bbva-hiring-paperless.appspot.com/crear-cuenta/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake BBVA recruitment portal on a free appspot.com subdomain harvesting email + password; brand impersonation plus a phishing threat-intel hit on the primary domain. Do not enter credentials.

Risk Factors (5)
Impersonation of the BBVA banking brand on a domain BBVA does not own
Credential-capturing form (email + password) behind a fake recruitment pretext
Primary domain flagged as phishing in threat intelligence
Free shared-hosting subdomain (appspot.com) with unknown real creation date
Unranked domain claiming a top-tier brand identity
Domain age information unavailable

Details

Page Title

Portal de Contratación

Scan Type

public

Domain Name Analysis

The domain name 'bbva-hiring-paperless.appspot.com' uses the commercial generic top-level domain (.com) with subdomain 'bbva-hiring-paperless'. The registrable portion 'appspot' spans 7 characters split between 2 vowels and 5 consonants. Tokenizing the label suggests two words: app, spot. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://bbva-hiring-paperless.appspot.com/crear-cuenta/

Page Load Overview

3.24s
Total Load Time
828 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:55%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:455 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

government public service89% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
89%
finance banking
86%
adult content
40%
corporate business
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8192.178.183.153Google · CDNUnited States
AS15169Google LLC
8142.251.127.153Google · CDNUnited States
AS15169Google LLC
162--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B2019E499CF0896D02209359BCE1F814CC97E74BB315ED5071EE90AC1FD4B8B8D9B5B8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:hR056M8qHjgIhcqsKWlDVojR+dqAEdeFULApKY/mqJmrNK7s0FftI:hRc6tqDL8KWBVbd7EaUxYJqK7s0FVI

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:681:IAAAKAAIAAAAEAAAAAAAIAAAAAAAAQAAAAAAAAAAAAAAAAAAgAAAAAAAAAAAAAAAAAAAAAAAgEAAABAAEAAAACAAAAAAAEAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:001f1f1f1f1f1f1f
Perceptual Hash:986661665a5b665e
Difference Hash:bcb47e3e3e3e3e38
Wavelet Hash:000f1f1f0f0f1f1f
Color Hash:#ac6053

Scan History

Scan history not available

Unable to load historical scan data