URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 16 d ago. Click Reanalyze to run a fresh scan.
PHISHING · MEDIUM CONFIDENCE

Phishing detected

brand banco-nacional scan id 19a7832d duration 12.64s signals 2 failing / 12
Risk score 0.90
90 / 100 · High risk
Tags
https :// zerophishex . fly . dev /scans/bd0d82da-f491-4d30-8177-9f39aa6db25e
flagged registered domain path protocol / query
URL hxxps://zerophishex[.]fly[.]dev/scans/bd0d82da-f491-4d30-8177-9f39aa6db25e
Host zerophishex[.]fly[.]dev
Registered domain fly[.]dev
Brand banco-nacional
Screenshot https://cdn.zerophish.ai/b5ea9683-8da0-405e-a81b-2b21d7f9736b.jpg
Scan ID 19a7832d-e8f8-48d6-ab17-006a867b8ade
16 d ago
PHISHING zerophishex.fly.dev view →
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
×
Credential collection form
Credential collection form detected on the page
high
×
Visual similarity to known brand
90% structural similarity to banco-nacional
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render
b
banco-nacional
90%
Host zerophishex.fly.dev
Registered domain fly.dev
Scheme https
Content length 62428 B
HTTP 200 · text/html
Initial scan heuristic + LLM

The site presents itself as ‘banco-nacional’, but the domain ‘https://zerophishex.fly.dev’ does not belong to this brand, indicating a phishing attempt. The site has a login form that could be used for credential harvesting, raising its phishing score. There is no favicon impersonation detected. Due to these factors, site was classified as phishing with medium confidence.