Security Scan Report: noctisolucoes.com.br

Submitted: Dec 5, 2025, 10:59:32 AMCompleted: Dec 5, 2025, 11:00:14 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 3 countries across 6 domains to perform 22 HTTP transactions. The main domain is noctisolucoes.com.br and was registered NaN years ago.

Submitted URL: https://noctisolucoes.com.br/data/load/gggg/arubaaufix/web/authen.php

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Phishing page impersonating Aruba Webmail; do not enter credentials.

Risk Factors
Brand impersonation (Aruba) on unrelated domain
Credential harvesting form (email + password)
Unranked domain in Cisco Umbrella
Very low legitimacy signals
Mismatched copyright notice
Domain age information unavailable

Details

Page Title

Aruba Webmail

Scan Type

public

Language

🇮🇹

Italian

(43% confidence)

Category

unknown

(0%)

Domain Information

Within the Brazilian country-code top-level domain (.com.br), 'noctisolucoes.com.br' is registered without a subdomain. Its registrable label 'noctisolucoes' stretches across 13 characters containing 6 vowels alongside seven consonants. Tokenizing the label suggests six words: n, oct, iso, lu, coe, s. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://noctisolucoes.com.br/data/load/gggg/arubaaufix/web/authen.php

Page Load Overview

3.34s
Total Load Time
22
HTTP Requests
6
Domains
2.3 MB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:43%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:43%
Script Type:Latin
HTML Lang Attribute:en
Text Length:470 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
14177.91.172.6Paiçandu, Paraná, Brazil
AS262355VSX Networks
2104.17.24.14United States
AS13335CLOUDFLARENET
2104.17.25.14United States
AS13335CLOUDFLARENET
2142.250.185.131United States
AS15169GOOGLE
22606:4700::6811:190eUnited States
AS13335CLOUDFLARENET
22a00:1450:4001:80b::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
22606:4700::6811:180eUnited States
AS13335CLOUDFLARENET
22a00:1450:4001:830::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
1142.251.140.170United States
AS15169GOOGLE
229--

Detected Technologies2

JQueryv3.5.1
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T186022F2020F14AB7169786A13850FF597ECAF307DA078944B6FC0E961F87D86CD836B9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nOfCKYBgfv20i718wSd/6pTjolrmCBqfjkX2gZ6/SiPGEE3vlVYlbcO:OaKYBIeuPr0NGbVY2O

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8524:yqDQwAmGAoBwyZ4bGBhJEHQRIIAQwkgwVCEAnIxFESNCX4JICmwAgIhKgRACSgUgwAFLZLiohBTBq8CbDBWHoZI9NwAwgCBo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcf878783ffffff
Perceptual Hash:b838c6cf38927339
Difference Hash:051e1a191b13000c
Wavelet Hash:f080808081ffdfc7
Color Hash:#483a78

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data