Security Scan Report: wetransfer550.blob.core.windows.net

Site favicon
Submitted: Nov 22, 2025, 12:00:23 PMCompleted: Nov 22, 2025, 12:01:06 PMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 3 countries across 5 domains to perform 20 HTTP transactions. The main domain is wetransfer550.blob.core.windows.net.

Submitted URL: https://wetransfer550.blob.core.windows.net/file589132014888291392103/webm.html

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Page is a confirmed phishing scam harvesting Aruba webmail credentials.

Risk Factors
Cloud storage hosting (blob.core.windows.net) combined with credential collection
Password fields on an untrusted, likely newly‑registered domain
Impersonation of a legitimate service (Aruba Webmail) on a suspicious URL
Absence of noindex tags indicating attempt to be indexed by search engines
Domain age information unavailable

Details

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'wetransfer550.blob.core.windows.net' on the network infrastructure generic top-level domain (.net) and includes subdomain 'wetransfer550.blob.core'. Its registrable label 'windows' stretches across 7 characters with two vowels and 5 consonants. Word splitting yields 1 word: windows. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://wetransfer550.blob.core.windows.net/file589132014888291392103/webm.html

Page Load Overview

0.31s
Total Load Time
20
HTTP Requests
5
Domains
433 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:494 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1220.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
3151.101.129.229San Francisco, California, United States
AS54113FASTLY
2104.17.24.14United States
AS13335CLOUDFLARENET
2142.250.181.227United States
AS15169GOOGLE
1104.16.175.226United States
AS13335CLOUDFLARENET
1142.250.181.234United States
AS15169GOOGLE
1104.17.25.14United States
AS13335CLOUDFLARENET
1104.16.174.226United States
AS13335CLOUDFLARENET
12606:4700::6810:aee2United States
AS13335CLOUDFLARENET
12a00:1450:4001:801::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
2014--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19022305060F4083751A785D83AA4670A3EC6E21BCA57454477FC4BE81FDBC93AE53A2E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nZF+zgW2JuYoL/ve/c7vNt/jqEGEuPMsa3pTgd4rZN6RFqLQQxKAj:ZF+EW2JKck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10547:EJQTAaQBAkGEABCDtUlALASpA1CUmAiyAAYwq8aCDZHochOqZhxYuIWAkCAVAlgJONCKm6h5DogYoQpgA0WACAEoBmeCBFiI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcf878783cfffff
Perceptual Hash:b033c7cc7ec33838
Difference Hash:041e1a1f3f3a000c
Wavelet Hash:f38183818107ffe7
Color Hash:#8b79d2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data