Security Scan Report: archipelagic32reinsulate.blob.core.windows.net

Redirected to: https://aruba0managehosting.blob.core.windows.net/webmail/webm.html

Site favicon
Submitted: Dec 9, 2025, 4:14:58 PMCompleted: Dec 9, 2025, 4:15:18 PMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 4 countries across 7 domains to perform 26 HTTP transactions. The main domain is aruba0managehosting.blob.core.windows.net and was registered NaN years ago.

Submitted URL: https://archipelagic32reinsulate.blob.core.windows.net/miai93ku2x2j/iCJRZZd.html

Effective URL: https://aruba0managehosting.blob.core.windows.net/webmail/webm.htmlRedirected

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed phishing site impersonating Aruba Webmail; do not enter credentials.

Risk Factors
Cloud storage hosting with credential‑harvesting form
Brand impersonation of Aruba Webmail on a non‑official domain
Multiple password fields collected on an untrusted domain
Redirects between cloud storage URLs
Domain age information unavailable

Details

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

Within the network infrastructure generic top-level domain (.net), 'archipelagic32reinsulate.blob.core.windows.net' is registered, featuring subdomain 'archipelagic32reinsulate.blob.core'. Its registrable label 'windows' stretches across 7 characters containing two vowels alongside five consonants. Word splitting yields one word: windows. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://archipelagic32reinsulate.blob.core.windows.net/miai93ku2x2j/iCJRZZd.html

Page Load Overview

1.94s
Total Load Time
26
HTTP Requests
7
Domains
608 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:434 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13104.17.25.14United States
AS13335CLOUDFLARENET
1104.16.175.226United States
AS13335CLOUDFLARENET
1192.178.170.95United States
AS15169GOOGLE
1172.217.18.3United States
AS15169GOOGLE
162.149.186.150Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
120.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
1104.16.174.226United States
AS13335CLOUDFLARENET
1104.17.24.14United States
AS13335CLOUDFLARENET
12606:4700::6811:180eUnited States
AS13335CLOUDFLARENET
12606:4700::6810:afe2United States
AS13335CLOUDFLARENET
2614--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B622515060F4083751A785C83AA8670A3EC6E21BCA57460477FC4BE81FD7C93AE57A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nZF+zgW2Ju8oL/Yb/c7vNM/jqlGEuPMsa3pTgd4rZN6RFqLQQxKAj:ZF+EW2Jqck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10309:AmQAMSqRUEiCAUyANGDADGA7gRCUmFF0BBYcgpHBOIHgpQMadRJANCAoQESFAsQAAJiIO4GbDQ3AAWp0JqGQBgMQEGnEAB0E

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff87878787ffffff
Perceptual Hash:b030c7cf4cccc733
Difference Hash:151e183f1f80120c
Wavelet Hash:f0808181017fcfc7
Color Hash:#ac5397

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data