Security Scan Report: arubabuckets3cdn.blob.core.windows.net

Submitted: Nov 21, 2025, 10:21:52 AMCompleted: Nov 21, 2025, 10:24:47 AMpubliccompleted
Loading additional data...

Summary

This website contacted 13 IPs in 3 countries across 5 domains to perform 19 HTTP transactions. The main domain is arubabuckets3cdn.blob.core.windows.net.

Submitted URL: https://arubabuckets3cdn.blob.core.windows.net/managehosting/webm.html

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed phishing site impersonating Aruba Webmail; do not enter credentials.

Risk Factors
Cloud storage hosting with credential collection
Brand impersonation of Aruba Webmail on a non‑official domain
Login form with password fields on an untrusted domain
Domain appears newly registered (no age data)
Domain age information unavailable

Details

Primary Scan Blocked — Fallback Capture Shown

The primary scanner could not load this page (possible bot protection). The screenshot and page details shown were captured by a fallback browser that loaded the page successfully.

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

Within the network infrastructure generic top-level domain (.net), 'arubabuckets3cdn.blob.core.windows.net' is registered, featuring subdomain 'arubabuckets3cdn.blob.core'. The core label 'windows' covers 7 characters holding 2 vowels versus five consonants. Segmentation suggests one word: windows. Expect seven characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://arubabuckets3cdn.blob.core.windows.net/managehosting/webm.html

Page Load Overview

0.26s
Total Load Time
19
HTTP Requests
5
Domains
581 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:434 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1120.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
3104.16.175.226United States
AS13335CLOUDFLARENET
2142.250.185.131United States
AS15169GOOGLE
2104.17.25.14United States
AS13335CLOUDFLARENET
1142.250.185.202United States
AS15169GOOGLE
1104.17.24.14United States
AS13335CLOUDFLARENET
1104.16.174.226United States
AS13335CLOUDFLARENET
12606:4700::6811:180eUnited States
AS13335CLOUDFLARENET
12606:4700::6811:190eUnited States
AS13335CLOUDFLARENET
12606:4700::6810:aee2United States
AS13335CLOUDFLARENET
1913--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C122411060F0093751A785C93AA8670A3EC2E21BCA5B450477FC4BE81FD7C93AE57A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nZF+zgW2JuSToH/Yz/c7vNw/jqRGEuPMsa3pTgd4rZN6RFqLQQxKAj:ZF+EW2JrOck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10351:REYkCySFQHKAMQHAtEFMJIg/IBJWjCB4AA9QRoiAjBNgYgFAdgFDsxg0AwZqEFEAsoWOCb7/vAiASApoaoOkAAMGgGmDGEgQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff87878787ffffff
Perceptual Hash:b030c7cf4cccc733
Difference Hash:151e183f1f80120c
Wavelet Hash:f0808181017fcfc7
Color Hash:#74862d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data