Security Scan Report: bonsec.hylandcloud.com

Redirected to:
https://bonsec.hylandcloud.com/241appnet/Login.aspx
Site favicon
Submitted: May 14, 2026, 5:14:04 PMCompleted: May 14, 2026, 5:15:49 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 39 HTTP transactions. The main domain is bonsec.hylandcloud.com and was registered NaN years ago.

Submitted URL: https://bonsec.hylandcloud.com

Effective URL: https://bonsec.hylandcloud.com/241appnet/Login.aspxRedirected

The Cisco Umbrella rank of the primary domain is #15,949 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

The site hosts a login form and shows critical IDS alerts for C2 and data exfiltration, indicating a high‑risk credential phishing attempt despite its age and reputation.

Risk Factors
Critical IDS alerts (malware C2 beacon, data exfiltration)
Credential login form on a subdomain
Large POST requests to external servers
Domain age information unavailable

Details

Page Title

Sign In - OnBase 811w5a

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(52%)

Domain Information

The domain 'bonsec.hylandcloud.com' uses the commercial generic top-level domain (.com), featuring subdomain 'bonsec'. Count 11 characters in 'hylandcloud' holding 3 vowels versus 8 consonants. Splitting it apart reveals two words: hyland, cloud. Expect 5.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bonsec.hylandcloud.com

Page Load Overview

8.44s
Total Load Time
39
HTTP Requests
1
Domains
173 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-us
Text Length:144 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software52% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
52%
documentation technical
43%
government public service
31%
adult content
30%
news media journalism
29%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
39205.235.80.124Reston, Virginia, United States
AS12025Iron Mountain Data Center
391--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1564207430A198D61EE0000EAE495FCD058AA752AC3C2D889E5DDB00D33FEFE59D667DE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:sW+WOBkhyCDwMVLexZ8eG2CNg98ASbojk/Vte3VDjYqCx1cMQR7nU4mgxlWIyIa0:sftktDTNexZxANAyojk/Vwh3ucMQRJjF

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12238:4KQkqBChIUFlQMyIAJYIJaDhJBWMiCQJYMgqsQhJBMESCOTJESpQwAgQrAggZByWRykBIKAQPYAICUARQgACi4iYEQEMEAAQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f9fffffffff3f
Perceptual Hash:8f0f03c3033f1e7c
Difference Hash:d0602800000000c0
Wavelet Hash:0f0f0f0f0f0f0f0f
Color Hash:#77bf40

Other Hashes

Crop Resistant:d0602800000000c0

Scan History

Scan history not available

Unable to load historical scan data