preprod.booking.elladeviaggi.eminds.it - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned preprod.booking.elladeviaggi.eminds.it and returned a suspicious verdict (score 24), categorised as credential-harvest, impersonating microsoft. The page resolved to 95.110.205.249 on Aruba S.p.A. - Dedicated servers in IT. 6 domains and 3 IPs were contacted, over 37 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 24) · Confidence 36%
- Scanned URL:
https://preprod.booking.elladeviaggi.eminds.it/login.aspx - Domain: preprod.booking.elladeviaggi.eminds.it · IP: 95.110.205.249 · AS31034 · IT
- Server: Microsoft-IIS/8.0
- Page title: ELLADE viaggi - Prenotazioni traghetti on line
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 17 22: · subject CN=preprod.booking.elladeviaggi.eminds.it
- HTTP requests captured: 37 · cookies set: 1 · outgoing links: 16
- Scan tier: standard · observed 2026-08-21 10:12:25 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Matches phishing-kit family "Generic Office365 Harvester"
- Certificate issued < 48h ago
Detected technologies
- Microsoft IIS
- ASP.NET
- jQuery
- Bootstrap
Contacted infrastructure
- 95.110.205.249 - AS31034 Aruba S.p.A. - Dedicated servers (Italy)
- 104.17.24.14 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- preprod.booking.elladeviaggi.eminds.it
- cdnjs.cloudflare.com
- kit.fontawesome.com
- www.privacy.eminds.it
- prenotazioni.elladeviaggi.it
- www.eminds.it
- 95.110.205.249
- 104.17.24.14
- 172.64.147.188
- https://preprod.booking.elladeviaggi.eminds.it/login.aspx
- https://preprod.booking.elladeviaggi.eminds.it/Content/bootstrap.min.css
- https://preprod.booking.elladeviaggi.eminds.it/scripts/pickadate/themes/default.css
- https://preprod.booking.elladeviaggi.eminds.it/css/newrestyle-font.css
- https://preprod.booking.elladeviaggi.eminds.it/bundles/css/vessel?v=B3-OjtDocj4woZcfE0Zh0F2lLMUJ6qDlr356puXC8VU1
- https://cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.5.0/css/flag-icon.min.css
- https://preprod.booking.elladeviaggi.eminds.it/scripts/jquery-3.4.1.min.js
- https://preprod.booking.elladeviaggi.eminds.it/scripts/bootstrap.min.js
- https://preprod.booking.elladeviaggi.eminds.it/scripts/jquery-migrate-3.0.0.min.js
- https://preprod.booking.elladeviaggi.eminds.it/scripts/jquery.tools.min.js
- https://preprod.booking.elladeviaggi.eminds.it/bundles/js/vessel?v=aMu8hTZ8Tl6c2HOzoBxWt2nfi4quqetGxGBWrBjIHEw1
Questions about preprod.booking.elladeviaggi.eminds.it
- Is preprod.booking.elladeviaggi.eminds.it safe?
- No. MalwareAnalyzer scanned preprod.booking.elladeviaggi.eminds.it on 21 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- Does preprod.booking.elladeviaggi.eminds.it belong to microsoft?
- No. This page claims the identity of microsoft but nothing establishes that microsoft operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- How was preprod.booking.elladeviaggi.eminds.it checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of preprod.booking.elladeviaggi.eminds.it · Other microsoft phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan