Security Scan Report: lymphangioma255.blob.core.windows.net

Redirected to: https://arb9373h9f3hu383h3.blob.core.windows.net/man/webm.html

Site favicon
Submitted: Dec 10, 2025, 1:55:17 PMCompleted: Dec 10, 2025, 1:56:10 PMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 3 countries across 8 domains to perform 25 HTTP transactions. The main domain is arb9373h9f3hu383h3.blob.core.windows.net.

Submitted URL: https://lymphangioma255.blob.core.windows.net/4k8di50imt/96RDjvv.html

Effective URL: https://arb9373h9f3hu383h3.blob.core.windows.net/man/webm.htmlRedirected

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing scam; do not enter credentials and report the site.

Risk Factors
Cloud storage hosting with credential collection
Password fields on a suspicious domain
Impersonation of a legitimate service (Aruba Webmail)
Likely newly registered domain
Noindex tag missing
Domain age information unavailable

Details

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'lymphangioma255.blob.core.windows.net' on the network infrastructure generic top-level domain (.net) and includes subdomain 'lymphangioma255.blob.core'. The registrable portion 'windows' spans 7 characters split between 2 vowels and five consonants. It segments into 1 word: windows. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lymphangioma255.blob.core.windows.net/4k8di50imt/96RDjvv.html

Page Load Overview

40.66s
Total Load Time
25
HTTP Requests
8
Domains
608 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:434 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12104.16.174.226United States
AS13335CLOUDFLARENET
1104.16.175.226United States
AS13335CLOUDFLARENET
1104.17.24.14United States
AS13335CLOUDFLARENET
1142.250.186.138United States
AS15169GOOGLE
1142.250.184.227United States
AS15169GOOGLE
120.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
162.149.186.150Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
12a00:1450:4001:80b::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
1104.17.25.14United States
AS13335CLOUDFLARENET
12606:4700::6810:afe2United States
AS13335CLOUDFLARENET
2514--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13222635060F4083751A785D93AA8671A3EC2D21BCA57450477FC4BE81FD7C83AE57A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nZF+zgW2JuegotL/Yu/c7vN//jqIGEuPMsa3pTgd4rZN6RFqLQQxKAj:ZF+EW2JHbcck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10318:gmco8SRBaGLggADANMlaBAAvApY8mAQ8BQz0SiDCHAlIJAEIZBBAeDoAIIgQAEBaAJiIC4C57QzTAOphQtDEAFEBAGmylSgA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff87878787ffffff
Perceptual Hash:b030c7cf4cccc733
Difference Hash:151e183f1f80120c
Wavelet Hash:f0808181017fcfc7
Color Hash:#1f934e

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data