URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · HIGH CONFIDENCE
No phishing signals detected
Risk score
0.02
2 / 100 · Low risk
URL anatomy
https
://
google
.
com
flagged
registered domain
path
protocol / query
Indicators of compromise
| URL | hxxps://Google[.]com | |
| Host | google[.]com | |
| Brand | ||
| Screenshot | https://cdn.zerophish.ai/59e92fe0-8460-4ac0-b69b-39354733534e.jpg | |
| Scan ID | 38ca547a-424d-40e1-bdfc-f70507c7d5b4 |
Related detections
|
283 d ago
|
REVIEW | google.com | safe |
|
325 d ago
|
REVIEW | www.google.com | safe |
|
335 d ago
|
PHISHING | www.google.com | view → |
Detection signals
Brand typo-squat detected
Registered brand domain
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
100% structural similarity to Google
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
Brand impersonation
G
Google
google.com
100%
Technical profile
| Host | google.com |
| Registered domain | google.com |
| Scheme | https |
| Content length | 324025 B |
| HTTP | 200 · text/html |
| JARM | 0d39b39b30d30d37d20320327d20122de7c02fe862e334985aa656e5df0651 |
| Redirect hops | 2 |
Analyst summary
Initial scan
Verdict: Legitimate (Google)
What the page presents itself as
- The page title and navigation show “Google” and links such as “Gmail”, “Images”, and “Sign in”.
- The OCR content references Google’s ecosystem, e.g., “Choose Chrome, the browser built by Google” and text about Chrome updates and terms.
Suspicious elements checked
-
Credential/credential-collection form: Not observed in the provided HTML/OCR. While there is a “Sign in” link (to
https://accounts.google.com/...), there is no visible embedded login form collecting credentials on this page. - Fake security warnings / urgency cues: No alerts like account suspension, “verify now,” or similar urgency or threat messaging appears in the OCR text.
-
Brand mismatch indicators: The URL is
https://Google.com(and the content includes multiple Google properties). The visible content strongly matches Google’s normal layout and messaging. -
Suspicious redirects / off-domain identity: Links shown (e.g.,
mail.google.com,accounts.google.com,about.google.com, andstore.google.com) are consistent with Google-owned domains in the HTML snippet.
Conclusion
- Based on the strong brand consistency (Google page elements, Chrome promotional text, and links to Google-owned subdomains) and the absence of any in-page credential harvesting UI, this does not exhibit common phishing patterns.
Notes / limitations
-
The URL casing/domain formatting uses
Google.com, but the links in the HTML are to standard Google domains (not lookalike domains). With the evidence provided, the page is best classified as legitimate.