URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
PHISHING · MEDIUM CONFIDENCE
Phishing detected
Risk score
0.90
90 / 100 · High risk
URL anatomy
https
://
zerophishex
.
fly
.
dev
/scans/bd0d82da-f491-4d30-8177-9f39aa6db25e
flagged
registered domain
path
protocol / query
Indicators of compromise
| URL | hxxps://zerophishex[.]fly[.]dev/scans/bd0d82da-f491-4d30-8177-9f39aa6db25e | |
| Host | zerophishex[.]fly[.]dev | |
| Registered domain | fly[.]dev | |
| Brand | banco-nacional | |
| Screenshot | https://cdn.zerophish.ai/b5ea9683-8da0-405e-a81b-2b21d7f9736b.jpg | |
| Scan ID | 19a7832d-e8f8-48d6-ab17-006a867b8ade |
Related detections
|
16 d ago
|
PHISHING | zerophishex.fly.dev | view → |
Detection signals
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
Credential collection form detected on the page
high
Visual similarity to known brand
90% structural similarity to banco-nacional
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
Brand impersonation
b
banco-nacional
90%
Technical profile
| Host | zerophishex.fly.dev |
| Registered domain | fly.dev |
| Scheme | https |
| Content length | 62428 B |
| HTTP | 200 · text/html |
Analyst summary
Initial scan
The site presents itself as ‘banco-nacional’, but the domain ‘https://zerophishex.fly.dev’ does not belong to this brand, indicating a phishing attempt. The site has a login form that could be used for credential harvesting, raising its phishing score. There is no favicon impersonation detected. Due to these factors, site was classified as phishing with medium confidence.