Security Scan Report: lymphangioma255.blob.core.windows.net

Redirected to: https://arb9373h9f3hu383h3.blob.core.windows.net/man/webm.html

Site favicon
Submitted: Dec 10, 2025, 2:29:16 PMCompleted: Dec 10, 2025, 2:29:39 PMpubliccompleted
Loading additional data...

Summary

This website contacted 18 IPs in 3 countries across 8 domains to perform 28 HTTP transactions. The main domain is arb9373h9f3hu383h3.blob.core.windows.net.

Submitted URL: https://lymphangioma255.blob.core.windows.net/3s56h802cxn9/BiFjx7v4.html

Effective URL: https://arb9373h9f3hu383h3.blob.core.windows.net/man/webm.htmlRedirected

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Phishing page on cloud storage collecting credentials; avoid and report.

Risk Factors
Cloud storage hosting with credential collection
Password fields on non‑official domain
Brand impersonation of Aruba Webmail
New/unknown domain age
Domain age information unavailable

Details

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'lymphangioma255.blob.core.windows.net' on the network infrastructure generic top-level domain (.net) with subdomain 'lymphangioma255.blob.core'. The second-level label 'windows' is 7 characters long with 2 vowels and 5 consonants. Splitting it apart reveals one word: windows. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lymphangioma255.blob.core.windows.net/3s56h802cxn9/BiFjx7v4.html

Page Load Overview

2.58s
Total Load Time
28
HTTP Requests
8
Domains
608 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:434 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11216.58.209.202United States
AS15169GOOGLE
120.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
162.149.186.150Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
1151.101.1.229San Francisco, California, United States
AS54113FASTLY
18.6.112.0United States
AS13335CLOUDFLARENET
1216.58.209.195United States
AS15169GOOGLE
12a04:4e42:200::485United States
AS54113FASTLY
1151.101.129.229San Francisco, California, United States
AS54113FASTLY
12a00:1450:4026:803::2003Ireland
AS15169GOOGLE
12a00:1450:4026:802::200aIreland
AS15169GOOGLE
2818--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DC22601060F0083751A785D93AA8670A3EC6E61BCA57460477FC4BE81FD7C93AE57A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nZF+zgW2JuN8o6tM/Y4/c7vN1/jqGGEuPMsa3pTgd4rZN6RFqLQQxKAj:ZF+EW2JOstDck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10318:gmcI8SFJaGLhAADANMhYBAAvApY8mAA8hQ30QiDCHAlIYAEIZBBAeDoAIIgAAMBaQJiIi8C57QzTAOpjUtDEAlEAAGmwkSgA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff87878787ffffff
Perceptual Hash:b030c7cf4cccc733
Difference Hash:151e183f1f80120c
Wavelet Hash:f0808181017fcfc7
Color Hash:#a1c587

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data