Security Scan Report: ai4b0gklygpqx.blob.core.windows.net

Redirected to: https://itarbahost93.blob.core.windows.net/jh45g/webm.html

Submitted: Nov 26, 2025, 2:46:40 AMCompleted: Nov 26, 2025, 2:48:46 AMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 3 countries across 7 domains to perform 24 HTTP transactions. The main domain is itarbahost93.blob.core.windows.net.

Submitted URL: https://ai4b0gklygpqx.blob.core.windows.net/xf5j9pf1stybk4/B9uEuS.html

Effective URL: https://itarbahost93.blob.core.windows.net/jh45g/webm.htmlRedirected

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing scam; avoid interaction and report the site.

Risk Factors
Cloud storage hosting with credential collection forms
Impersonation of Aruba Webmail brand
Login form on a likely brand‑new domain
Misspelled credential prompts indicating social engineering
Combination of cloud storage + password fields triggers confirmed scam rule
Domain age information unavailable

Details

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'ai4b0gklygpqx.blob.core.windows.net' on the network infrastructure generic top-level domain (.net) and includes subdomain 'ai4b0gklygpqx.blob.core'. The second-level label 'windows' is 7 characters long with 2 vowels and 5 consonants. Word splitting yields one word: windows. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ai4b0gklygpqx.blob.core.windows.net/xf5j9pf1stybk4/B9uEuS.html

Page Load Overview

0.17s
Total Load Time
24
HTTP Requests
7
Domains
608 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:434 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1520.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
3104.16.175.226United States
AS13335CLOUDFLARENET
2142.250.186.131United States
AS15169GOOGLE
2104.17.24.14United States
AS13335CLOUDFLARENET
162.149.186.150Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
1142.250.186.170United States
AS15169GOOGLE
12606:4700::6810:afe2United States
AS13335CLOUDFLARENET
1104.17.25.14United States
AS13335CLOUDFLARENET
1104.16.174.226United States
AS13335CLOUDFLARENET
12a00:1450:4001:82b::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
2414--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11A22515060F4087751A789C83AA8670A3EC6D20BCA57460477FC4BE81FD7C93AE57A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TZF+zgW2JuQoj/YY/c7vNp/jqOGEuPMsa3pTgd4rZN6RFqLQQxKAj:VF+EW2JJck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10339:EAvBAcoAdIIEliQORJAgIwKchkBQA4ENXUCDMAgBAgWE4JQOSoGdFA8wIG2K4AEgIWgNBhoJ7yAXjiKVQ4gHCSxLHoigA1aE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefec6fefefafec3
Perceptual Hash:f5c720cd28db229b
Difference Hash:02064c0a32123096
Wavelet Hash:2e2602021e1a0c00
Color Hash:#3a6378

Other Hashes

Crop Resistant:02064c0a32123096

Scan History

Scan history not available

Unable to load historical scan data