URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · HIGH CONFIDENCE
No phishing signals detected
Risk score
0.04
4 / 100 · Low risk
URL anatomy
https
://
github
.
com
/nemonicon/zerophishEx
flagged
registered domain
path
protocol / query
Indicators of compromise
| URL | hxxps://github[.]com/nemonicon/zerophishEx | |
| Host | github[.]com | |
| Brand | GitHub | |
| Screenshot | https://cdn.zerophish.ai/e2e8dc08-7600-405f-be64-00340a2e7088.jpg | |
| Scan ID | 25d394f9-8e30-4e65-8d0e-ba5b89713d9e |
Related detections
|
17 d ago
|
SAFE | github.com | safe |
|
17 d ago
|
SAFE | GitHub.com | safe |
|
17 d ago
|
SAFE | github.com | safe |
|
17 d ago
|
SAFE | github.com | safe |
|
419 d ago
|
REVIEW | github.com | safe |
|
515 d ago
|
REVIEW | github.com | safe |
|
516 d ago
|
REVIEW | github.com | safe |
|
520 d ago
|
REVIEW | github.com | safe |
Detection signals
Brand typo-squat detected
Registered brand domain
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
100% structural similarity to GitHub
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · certificate validated by ApiFlash
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
Brand impersonation
G
GitHub
github.com
100%
Technical profile
| Host | github.com |
| Registered domain | github.com |
| Scheme | https |
| Content length | 318878 B |
| HTTP | 200 · text/html |
Analyst summary
Initial scan
The rendered webpage is a GitHub 404 error page. There are no visible elements that could be used for phishing, such as a fake login form or unexpected rewards. The website’s content matches the GitHub brand perfectly. There is no favicon impersonation, credential form, or any suspicious domain related to phishing.