URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 242 d ago. Click Reanalyze to run a fresh scan.
REVIEW · MEDIUM CONFIDENCE

Review required

brand escaping.work scan id 04c4ebe6 duration signals 0 failing / 0
Risk score 0.20
20 / 100 · —
Tags
https :// .
flagged registered domain path protocol / query
URL hxxps://escaping[.]work/sora-invites/
Brand escaping.work
Screenshot https://cdn.zerophish.ai/355eaf75-98ad-4d58-ad3c-ccde105810ba.jpg
Scan ID 04c4ebe6-ac1c-491a-beff-44a54eaca3a3

No detection signals on this scan — it predates the signal pipeline. Re-analyze to capture them.

Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

No technical metadata captured for this scan.

Initial scan heuristic + LLM

The site appears to be a service set up to generate codes for another site, Sora. The website itself, escaping.work, does not appear to be trying to impersonate another brand, and while the purpose of the site is somewhat unclear, it does not appear to incorporate common social engineering techniques generally used in phishing attacks, such as fake login prompts or alerts about the user’s account. The site seems legitimate, but because the purpose is unclear, it is suggested to proceed with caution when using such sites.