Security Scan Report: commerciality1norito.blob.core.windows.net

Redirected to: https://arb9373h9f3hu383h3.blob.core.windows.net/man/webm.html

Site favicon
Submitted: Dec 10, 2025, 3:12:22 PMCompleted: Dec 10, 2025, 3:12:45 PMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 3 countries across 8 domains to perform 28 HTTP transactions. The main domain is arb9373h9f3hu383h3.blob.core.windows.net.

Submitted URL: https://commerciality1norito.blob.core.windows.net/mj7x3x3teeceo/QngOfI.html

Effective URL: https://arb9373h9f3hu383h3.blob.core.windows.net/man/webm.htmlRedirected

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed phishing scam targeting Aruba Webmail credentials.

Risk Factors
Cloud storage hosting with credential collection
Brand impersonation of Aruba Webmail
Password fields on untrusted domain
New/unknown domain age
Redirect chain obscuring final destination
Domain age information unavailable

Details

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'commerciality1norito.blob.core.windows.net' uses the network infrastructure generic top-level domain (.net); it also runs on subdomain 'commerciality1norito.blob.core'. The registrable portion 'windows' spans 7 characters split between 2 vowels and five consonants. It segments into one word: windows. Median word length comes out to seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://commerciality1norito.blob.core.windows.net/mj7x3x3teeceo/QngOfI.html

Page Load Overview

4.37s
Total Load Time
28
HTTP Requests
8
Domains
608 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:434 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2216.58.209.202United States
AS15169GOOGLE
2216.58.210.131United States
AS15169GOOGLE
28.6.112.0United States
AS13335CLOUDFLARENET
2104.16.174.226United States
AS13335CLOUDFLARENET
220.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
262.149.186.150Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
2104.16.175.226United States
AS13335CLOUDFLARENET
28.47.69.0United States
AS13335CLOUDFLARENET
22a06:98c1:3123:8000::United States
AS13335CLOUDFLARENET
22606:4700::6810:afe2United States
AS13335CLOUDFLARENET
2814--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11D22515060F0083751A785D93AA9670A3EC2E21BCA57450477FC4BE81FD7C93AE57A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nZF+zgW2Juzot/Y4/c7vN1/jqGGEuPMsa3pTgd4rZN6RFqLQQxKAj:ZF+EW2JCck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10318:gmcI8ShBaGLhAADANMhYBAAvgt48mAA8hQz0QiDCHAlIYAEJZBBAeDoAIIgAAEBaAJmIC8C57QzTAOpxQtDEAlEAAGmwkSgA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff87878787ffffff
Perceptual Hash:b030c7cf4cccc733
Difference Hash:151e183f1f80120c
Wavelet Hash:f0808181017fcfc7
Color Hash:#7753ac

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data