Security Scan Report: hennesseyllchabina677.blob.core.windows.net

Submitted: Sep 28, 2026, 3:14:05 AMCompleted: Sep 28, 2026, 3:14:38 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Phishing page on an Azure blob bucket mimicking sekure.net: a 'session expired' email+password login form exfiltrates entered credentials to mail.ananworks.com. Do not enter any credentials.

Risk Factors (5)
Credential/password form harvesting email + password on a shared cloud-storage host
Confirmed JavaScript exfiltration of entered password to an unrelated external domain
Victim email embedded in URL fragment — phishing-kit victim-tracking token
Impersonation of sekure.net on a non-official domain (hennesseyllchabina677.blob.core.windows.net)
Unranked hosting subdomain of unknown creation date; right-click blocking anti-analysis technique
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'hennesseyllchabina677.blob.core.windows.net' uses the network infrastructure generic top-level domain (.net); it also runs on subdomain 'hennesseyllchabina677.blob.core'. The second-level label 'windows' is 7 characters long holding 2 vowels versus five consonants. Breaking it apart gives 1 word: windows. The median word length lands at 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://hennesseyllchabina677.blob.core.windows.net/gcsmea2377/cent.html#eriq@sekure.net

Page Load Overview

0.88s
Total Load Time
229 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:63%
Script:Latin
Direction:ltr

Detection Details

Text Length:104 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical30% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

healthcare medical
30%
news media journalism
27%
adult content
26%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1135.130.64.96Azure · CLOUDDulles, Virginia, United States
AS8075Microsoft Corporation
1142.251.127.95Google · CDNUnited States
AS15169Google LLC
1142.251.151.119Google · CDNUnited States
AS15169Google LLC
1178.63.16.224Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
1142.251.127.104Google · CDNUnited States
AS15169Google LLC
1142.251.152.119Google · CDNUnited States
AS15169Google LLC
1142.251.14.147Google · CDNUnited States
AS15169Google LLC
77--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15672535A65F310952533E07C2BBB53082235D0079A4BCE28BE9C57854F5E7A8AEB27CD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:HLs+o0R+TOyMuBarJ2/PRrwg1Ji4SbR3v+Cvqd/dQKyTSBgzZ7CZrJycpgtAtDGt:HoCuo6KiCYSo6jb

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:16684:tKiB2g0U0CKokABOZAg7GpAZsAEEgBCYcAApD1DpBYijWIBTbIFCAEwiRRYoixAAClmQigIDQGjRAbUSIIBBAREADEgwajQh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181824241800
Perceptual Hash:9999666699996666
Difference Hash:000830b24c4c3000
Wavelet Hash:00003838e4fcfcfc
Color Hash:#bf4060

Other Hashes

Crop Resistant:000830b24c4c3000

Scan History

Scan history not available

Unable to load historical scan data