Security Scan Report: warubabsls.vercel.app

Redirected to:
blob:https://f003.backblazeb2.com/41f3971e-a848-4773-b697-b817c1256f0e
Submitted: Sep 29, 2026, 8:50:03 PMCompleted: Sep 29, 2026, 8:50:37 PMpubliccompleted

This website contacted 12 IPs in 3 countries across 11 domains to perform 16 HTTP transactions. The main domain is and was registered 14 years ago.

Submitted URL: https://warubabsls.vercel.app/

Effective URL:

blob:https://f003.backblazeb2.com/41f3971e-a848-4773-b697-b817c1256f0e
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake Aruba S.p.A. webmail login hosted on a vercel.app subdomain, serving a password-capture form assembled via a blob: URL. Brand impersonation plus credential collection — do not enter credentials.

Risk Factors (4)
Brand impersonation of Aruba S.p.A. webmail on an unrelated vercel.app subdomain
Credential-harvesting login form (password + username fields)
Phishing page assembled dynamically via blob: URL on Backblaze B2 storage
Multiple redirects obfuscating the source of the login page
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'warubabsls.vercel.app' is registered, featuring subdomain 'warubabsls'. Its registrable label 'vercel' stretches across 6 characters split between two vowels and 4 consonants. It segments into 2 words: ver, cel. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://warubabsls.vercel.app/

Page Load Overview

0.46s
Total Load Time
451 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Text Length:249 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business46% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

corporate business
46%
government public service
40%
technology software
39%
finance banking
30%
news media journalism
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
564.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
145.11.36.16Schiphol, North Holland, Netherlands
AS40401Backblaze Inc
1104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.127.95Google · CDNUnited States
AS15169Google LLC
1104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
162.149.158.90Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
1612--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D42AF4CA0ED88770B8E8F43B9A45A87B366D11F87476243F35DBAC81BE6852C885C75

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:QNnJ7dkrVFEv2vdFY6j7+vWaYlOLUDvmVVFC52vleExUt+MHPVYNj:EdkrVSOvdfv+vtWOWBq

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12555:FgIAoARpKJMAQgBXlJjHIhGIFEiIRtSgg2hAICAysIAjDid0WAsFwHBwoxsESMqkLBE4/LHQhixEBEAJclgEAIJSrigwji0w

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffcbcf87c7f3ff
Perceptual Hash:b19ccc3333cc3369
Difference Hash:0006361e0a180606
Wavelet Hash:ff8183818187f1e7
Color Hash:#c58799

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data