URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · HIGH CONFIDENCE
No phishing signals detected
Risk score
0.02
2 / 100 · Low risk
URL anatomy
https
://
www
.
zaproxy
.
org
/docs/testapps/altoroj/
flagged
registered domain
path
protocol / query
Indicators of compromise
| URL | hxxps://www[.]zaproxy[.]org/docs/testapps/altoroj/ | |
| Host | www[.]zaproxy[.]org | |
| Registered domain | zaproxy[.]org | |
| Brand | ZAP (ZAP by Checkmarx) | |
| Screenshot | https://cdn.zerophish.ai/5259d33b-d446-4974-abde-033c32c69c1b.jpg | |
| Scan ID | 0db2106c-fe94-41f7-8d83-b93be10839bf |
Detection signals
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
98% structural similarity to ZAP (ZAP by Checkmarx)
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
Brand impersonation
Z
ZAP (ZAP by Checkmarx)
98%
Technical profile
| Host | www.zaproxy.org |
| Registered domain | zaproxy.org |
| Scheme | https |
| Content length | 78042 B |
| HTTP | 200 · text/html |
| JARM | 0d39b39b30d30d37d20320327d20122de7c02fe862e334985aa656e5df0651 |
| Redirect hops | 1 |
Analyst summary
Initial scan
Verdict: Legitimate
This page is documentation for ZAP (ZAP by Checkmarx)—specifically a guide titled “AltoroJ / testfire.net”. The URL is on the official ZAP documentation domain (zaproxy.org/docs/) and the HTML content consistently references ZAP tooling and scanning workflows.
Suspicious elements checked (phishing indicators)
- No credential-harvesting form found: The provided HTML/OCR text describes example users/credentials (e.g., “admin / admin” and “jsmith / demo1234”) only as test/demo inputs for security scanning configurations, not as an on-page login form.
- No fake security warnings / urgency cues: There are notes such as “📝 Note” about scan configuration, not account lockouts or urgent threats.
- No mismatched branding for a lookalike brand: The visible branding is ZAP (“ZAP By Checkmarx” logo) and the page title includes “ZAP – AltoroJ / testfire.net”, with no attempt to impersonate a separate consumer brand like PayPal.
- No suspicious redirects or domain deception: The page links to resources such as https://demo.testfire.net/ (intended for testing) and GitHub; nothing suggests a drive-by redirect to a login at a different domain.
Brand identification & URL relationship
- Identified brand on page: ZAP by Checkmarx.
- URL domain check: The page is served from zaproxy.org, which is the brand’s own documentation site. There is no evidence of a credible brand impersonation on an unrelated domain.
Conclusion
Given the consistent ZAP branding, documentation-style content, and absence of any credential-collection UI or account-theft social engineering patterns, this page is legitimate.