Security Scan Report: itarbahost93.blob.core.windows.net

Redirected to: https://itarbahost93.blob.core.windows.net/jh45g/webm.html

Submitted: Nov 26, 2025, 4:48:09 AMCompleted: Nov 26, 2025, 4:50:19 AMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 3 countries across 6 domains to perform 22 HTTP transactions. The main domain is itarbahost93.blob.core.windows.net.

Submitted URL: https://itarbahost93.blob.core.windows.net/jh45g/index.html

Effective URL: https://itarbahost93.blob.core.windows.net/jh45g/webm.htmlRedirected

The Cisco Umbrella rank of the primary domain is #44 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

High‑confidence phishing site harvesting Aruba Webmail credentials on a cloud storage domain.

Risk Factors
Cloud storage domain used to collect usernames and passwords
Brand impersonation of Aruba Webmail on a non‑official domain
Multiple password fields increase credential harvesting potential
Likely newly registered domain combined with phishing indicators
Domain age information unavailable

Details

Page Title

Webmail Aruba

Scan Type

public

Language

🇮🇹

Italian

(36% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'itarbahost93.blob.core.windows.net' uses the network infrastructure generic top-level domain (.net) with subdomain 'itarbahost93.blob.core'. The registrable portion 'windows' spans 7 characters with 2 vowels and 5 consonants. Tokenizing the label suggests one word: windows. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://itarbahost93.blob.core.windows.net/jh45g/index.html

Page Load Overview

0.29s
Total Load Time
22
HTTP Requests
6
Domains
607 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:36%
Script Type:Latin
HTML Lang Attribute:en
Text Length:434 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1320.209.87.193Milan, Lombardy, Italy
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
3104.16.174.226United States
AS13335CLOUDFLARENET
2104.17.24.14United States
AS13335CLOUDFLARENET
2142.250.185.131United States
AS15169GOOGLE
162.149.186.150Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
1104.16.175.226United States
AS13335CLOUDFLARENET
1142.250.186.106United States
AS15169GOOGLE
12a00:1450:4001:800::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:813::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
12606:4700::6810:aee2United States
AS13335CLOUDFLARENET
2214--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10122515060F4083751A789D83AA8671A3EC6D20BCA57460477FC4BE81FD7C93AE53A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TZF+zgW2Ju7oB/YY/c7vNp/jqOGEuPMsa3pTgd4rZN6RFqLQQxKAj:VF+EW2Jeck/ZfLQQgAj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10339:EAvBAcoANIIEliQORIAgIwKchkBQQ4ENXUCDMAgBAgWE4BQOSoGdFA8wIGWK4AEgIWoNBhoJ7yAXjCKVQwgHCSxLHoiAAVaE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefec6fefefafec3
Perceptual Hash:f5c720cd28db229b
Difference Hash:02064c0a32123096
Wavelet Hash:2e2602021e1a0c00
Color Hash:#6ce0d2

Other Hashes

Crop Resistant:02064c0a32123096

Scan History

Scan history not available

Unable to load historical scan data