Security Scan Report: 9bdaf5eb-f4c2-42d3-a3c6-102d753470d5-00-32edde2acv5j0.spock.replit.dev

Submitted: Oct 15, 2025, 2:47:21 AMCompleted: Oct 15, 2025, 2:48:55 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 4 HTTP transactions. The main domain is 9bdaf5eb-f4c2-42d3-a3c6-102d753470d5-00-32edde2acv5j0.spock.replit.dev.

Submitted URL: https://9bdaf5eb-f4c2-42d3-a3c6-102d753470d5-00-32edde2acv5j0.spock.replit.dev/

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Confirmed phishing scam impersonating Produbanco on a newly created unranked domain.

Risk Factors
Brand impersonation
Newly registered domain
Credential harvesting form
Hidden password field
Unranked domain
Domain age information unavailable

Details

Page Title

Produbanco - Login

Scan Type

public

Language

🇪🇸

Spanish

(51% confidence)

Category

finance banking

(58%)

Domain Information

The domain name '9bdaf5eb-f4c2-42d3-a3c6-102d753470d5-00-32edde2acv5j0.spock.replit.dev' uses the developer-focused generic top-level domain (.dev) with subdomain '9bdaf5eb-f4c2-42d3-a3c6-102d753470d5-00-32edde2acv5j0.spock'. The core label 'replit' covers 6 characters holding 2 vowels versus 4 consonants. Word splitting yields 2 words: rep, lit. Median word length comes out to 3 characters. 'rep' most often appears in Catalan. You will also see it in English and Chinese (Pinyin) contexts.

Screenshot

Security scan screenshot of https://9bdaf5eb-f4c2-42d3-a3c6-102d753470d5-00-32edde2acv5j0.spock.replit.dev/

Page Load Overview

73.45s
Total Load Time
4
HTTP Requests
1
Domains
169 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:51%
Script:Latin
Direction:ltr

Detection Details

Language Code:es
Detection Confidence:51%
Script Type:Latin
HTML Lang Attribute:es
Text Length:150 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking58% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
58%
cryptocurrency blockchain
34%
adult content
27%
technology software
26%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
434.82.58.13The Dalles, Oregon, United States
AS396982GOOGLE-CLOUD-PLATFORM
41--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13882A71A25F74131586FF2581BA79314366BD303E60ACEE43A9C53448F85EC98DB33AD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:/6tS5aOdD+/+IZh/ZU7+AW6yJ/QtFBgdkrLOmkLVXW0BOd2EPzbMOOe3lxmv+rUT:/lKWzYOO6P0TXFLfi+LsfG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17836:EqFEMjIQAQgsagJEQIERgpkAkvRKhICHCoDCUaAQAomBZAlCMFgGNdiIQCEhkhA0gANMUkCIgDVtCGBlCAAQcpAkiIiCJwUT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data