Security Scan Report: bbva-hiring-paperless.appspot.com

Site favicon
Submitted: Jul 21, 2026, 12:45:23 PMCompleted: Jul 21, 2026, 12:47:43 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is bbva-hiring-paperless.appspot.com and was registered NaN years ago.

Submitted URL: https://bbva-hiring-paperless.appspot.com/crear-cuenta

AI Security Verdict

Low Risk

Confidence: 88%

3
Risk Score

The site mimics BBVA hiring portal, collects credentials on a newly‑created appspot.com subdomain with obfuscated JS – high risk of phishing.

Risk Factors
Unknown subdomain age
Brand impersonation of a major financial institution
Credential collection form on untrusted subdomain
Highly obfuscated JavaScript
Safety Factors
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 3
Domain age information unavailable

Details

Page Title

Portal de Contratación

Scan Type

public

Language

🇪🇸

Spanish

(55% confidence)

Category

government public service

(89%)

Domain Information

The domain name 'bbva-hiring-paperless.appspot.com' uses the commercial generic top-level domain (.com), featuring subdomain 'bbva-hiring-paperless'. Its registrable label 'appspot' stretches across 7 characters holding 2 vowels versus 5 consonants. Tokenizing the label suggests 2 words: app, spot. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bbva-hiring-paperless.appspot.com/crear-cuenta

Page Load Overview

2.20s
Total Load Time
16
HTTP Requests
1
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:55%
Script:Latin
Direction:ltr

Detection Details

Language Code:es
Detection Confidence:55%
Script Type:Latin
HTML Lang Attribute:en
Text Length:455 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

government public service89% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
89%
finance banking
86%
adult content
40%
corporate business
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
16142.251.13.153Google · CDNUnited States
AS15169Google LLC
161--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T117A1442C684006A79637D592F8A3BD146884F74EE39CCA6CBB7B0194DBE2D98D4DD870

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:nn2L8NdjMesjiyy0ryJFVEwnGFEQJ71bhRr6NqMN2Y2g1TaBooT0Aah8Kg0o:nTlsey9EFV+Ff71bbNY2g5+zTEhlgp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4688:iAAAAAAAKBAlsWYhEkgEIqABIgABjAgJDKCBACNBYokDQIJMQAiZAQCCAjAAWixIACBUQAAAQRAIAgAgABAgSEANQiWQAEQA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:001f1f1f1f1f1f1f
Perceptual Hash:986641667a5b665e
Difference Hash:bcb47e363e3e3e38
Wavelet Hash:001f1f0f0f0f1f1f
Color Hash:#1f936f

Scan History

Scan history not available

Unable to load historical scan data