Security Scan Report: sonnelabs.com

Submitted: Sep 19, 2026, 5:15:07 AMCompleted: Sep 19, 2026, 5:15:27 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake 'Webmail login' page on sonnelabs.com harvesting email credentials, with the victim address [email protected] planted in the URL fragment — a clear phishing kit. Do not enter any credentials.

Risk Factors (5)
Credential login form (email + password) on a host that is not the mail provider
Victim email address '[email protected]' present in the URL fragment
Email domain ear.se mismatched against hosting domain sonnelabs.com
Page impersonates a webmail service ('Webmail login') it does not own
Login page located under an unrelated path (/network/index.html) on a non-mail domain
Domain age information unavailable

Details

Page Title

Webmail login

Scan Type

public

Domain Name Analysis

The domain name 'sonnelabs.com' uses the commercial generic top-level domain (.com). The core label 'sonnelabs' covers 9 characters holding 3 vowels versus six consonants. Segmentation suggests three words: son, ne, labs. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sonnelabs.com/network/index.html#threw@ear.se

Page Load Overview

0.69s
Total Load Time
215 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:177 chars
Detector Agreement:100%

Website Classification

Primary Category

real estate property52% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

real estate property
52%
government public service
47%
documentation technical
46%
news media journalism
37%
education learning
35%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5102.220.161.143Slovenia
AS197769VPS Dedicated LLC
1142.251.110.95Google · CDNUnited States
AS15169Google LLC
1151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1172.64.147.188Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
139--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17D42A52185D824A3145C3EAAC7E82D9D6B84F153AD134E40F1AE4E648FBBF4E294B65C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:t/3YFONfracVNWnpViOb20tELWtro89Z0/o8inMRq35cglx+lDds:CF2jFVYnzicEMlnwqNn+lG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12454:gRhoXMiFIhYwBQAykVCmgKiQEEDcIECCUrGOBC5KmFoFIDkhUAWAAAqAPDSiExhGEqsq4BhrY0ASjLiVCWUkcAshZDCl7AFJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7e7ffffffff
Perceptual Hash:b333cccc66269999
Difference Hash:0c0c1c4d14080000
Wavelet Hash:27272727033f0f0f
Color Hash:#b42dd2

Other Hashes

Crop Resistant:0c0c1c4d14080000

Scan History

Scan history not available

Unable to load historical scan data