Security Scan Report: 0000--carmennidia20.replit.app

Submitted: Sep 29, 2026, 8:36:16 AMCompleted: Sep 29, 2026, 8:36:50 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed phishing page impersonating Banco BHD on a replit.app subdomain, harvesting passwords, card coordinate codes, SMS OTPs and security answers, and flagged by Safe Browsing for Social Engineering.

Risk Factors (5)
Brand impersonation of a bank (BHD) on an unrelated shared hosting subdomain
Password field present with a multi-step credential/OTP/security-question harvesting flow
Google Safe Browsing Social Engineering threat
Requests card coordinate grid codes and SMS OTPs — full account takeover data
Hosted on free/instant replit.app namespace with no verifiable ownership (page-level age unknown)
Domain age information unavailable

Details

Page Title

BHD - Banca Móvil

Scan Type

public

Domain Name Analysis

Domain '0000--carmennidia20.replit.app' uses the application-focused generic top-level domain (.app) and includes subdomain '0000--carmennidia20'. Count 6 characters in 'replit' containing two vowels alongside 4 consonants. Word splitting yields 2 words: rep, lit. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://0000--carmennidia20.replit.app/

Page Load Overview

0.36s
Total Load Time
32 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:1,027 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
234.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1146.75.120.193Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
135.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
43--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T124A2B85672F31411D297E4B86BF38B063524C107D54BCA683AAC2684DFCAE91DAB37DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:WEOnpLOWkKgFfzMugFDHXLlu8JyQe2RSqPnt0MLd21FJE6/9HbGnwQOIe9IVVPGO:BrjFKlRk31F1HbGwR8HnVD4Edf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21914:IiIkbAAzxkKYngillIgBAhDBoSEGiFTitchANEKH6kBAEFVoIsiJmqBKgCkRQBagYgYRIIgWYl1ASVkAIgzFMC8RCiwxJwAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fcf8e0d8f8e0e0c0
Perceptual Hash:ddaa72a8dca872a8
Difference Hash:0000083010080000
Wavelet Hash:fcf8f0f8f8e0c0c0
Color Hash:#3a7853

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data