Security Scan Report: docs.google.com

Site favicon
Submitted: Nov 5, 2025, 10:41:10 PMCompleted: Nov 5, 2025, 10:42:56 PMpubliccompleted
Loading additional data...

Summary

This website contacted 12 IPs in 2 countries across 6 domains to perform 9 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://docs.google.com/document/d/13GPkRCD59uif6LYONOejsU-qP1Sy8fsnwDp1NAWkj8o/mobilebasic

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

High‑risk phishing document impersonating a bank on Google Docs.

Risk Factors
Brand impersonation on an unrelated domain
Threatening/urgent language to induce panic
Use of a reputable platform (Google Docs) to host potentially malicious content
Domain age information unavailable

Details

Page Title

Cuscatlan

Scan Type

public

Language

🇪🇸

Spanish

(46% confidence)

Category

malicious

(61%)

Domain Information

Within the commercial generic top-level domain (.com), 'docs.google.com' is registered, featuring subdomain 'docs'. Count 6 characters in 'google' containing three vowels alongside three consonants. Word splitting yields one word: google. The median word length lands at 6 characters. Most frequently, 'google' shows up in Sinhala. You will also see it in Danish and English contexts.

Screenshot

Security scan screenshot of https://docs.google.com/document/d/13GPkRCD59uif6LYONOejsU-qP1Sy8fsnwDp1NAWkj8o/mobilebasic

Page Load Overview

76.64s
Total Load Time
9
HTTP Requests
6
Domains
106 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:46%
Script:Latin
Direction:ltr

Detection Details

Language Code:es
Detection Confidence:46%
Script Type:Latin
Text Length:98 chars
Detector Agreement:100%

Website Classification

Primary Category

malicious61% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

malicious
61%
other
50%
suspicious phishing
48%
e-commerce
41%

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9142.251.140.174United States
AS15169GOOGLE
0142.250.186.163United States
AS15169GOOGLE
0142.250.185.241United States
AS15169GOOGLE
0142.250.186.170United States
AS15169GOOGLE
0142.250.185.163United States
AS15169GOOGLE
0142.250.186.65United States
AS15169GOOGLE
02a00:1450:4001:831::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
02a00:1450:4001:81c::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
02a00:1450:4001:813::2011Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
02a00:1450:4001:827::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
912--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1361360C057105CF8FE7A088391876DBA7E2D11BBE48214BBF3D4ADB12F966CA051627D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:d7EsweJqeJEhuxezoQzluNExjnrTNL9/ylosdnCgHvyVw/MOBiCpkDA4TilAPkOQ:TmtzCN60we+NfbnB7a9qJAPBCTDq

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:41436:WyKhGGQSASwHCWhD1IQDBEmEAABR9FEZMDTAAUiMFNOROrAK0aKZgCchEFxJYRLU40IADAZgTLZEQDXoJQPYj1LRhqhBBhiW

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00e7e7ffffffffff
Perceptual Hash:a727270d8d9d1933
Difference Hash:b00c0c0000000000
Wavelet Hash:00c7e4fcf0f0f0f0
Color Hash:#1f933a

Other Hashes

Crop Resistant:b00c0c0000000000

Scan History

Scan history not available

Unable to load historical scan data