URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 73 d ago. Click Reanalyze to run a fresh scan.
SUSPICIOUS · MEDIUM CONFIDENCE

Suspicious — review required

brand Unknown scan id 4f060ebf duration 20.23s signals 0 failing / 25
Risk score 0.55
55 / 100 · Medium risk
Tags
https :// vicehub . store
flagged registered domain path protocol / query
!
Email-auth posture (SPF/DMARC)
DMARC p=none (monitoring only) — domain can still be spoofed in mail
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "vicehub" reads as pronounceable / brand-like (randomness 38%)
↓ risk
Page language
Detected page language: Spanish (es) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://vicehub[.]store
Host vicehub[.]store
Screenshot https://cdn.zerophish.ai/5a5444be-5ffb-44c1-8d5b-7418f257d896.jpg
Scan ID 4f060ebf-9cd2-4360-8c7a-6d51b41407a7
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

Host vicehub.store
Registered domain vicehub.store
Scheme https
Content length 443712 B
HTTP 200 · text/html
DMARC policy p=none
SPF policy soft
MX records present
Initial scan heuristic + LLM

The page presents itself as a game pre-order store (“Reserva GTA VI Ultimate Edition + LED Vice City Gratis”) with urgency and social proof (“⚠️ UNIDADES LIMITADAS”, “Opiniones verificadas”, countdown timer). It includes multiple claims of safety and legitimacy (“Pago 100% seguro”, “Métodos de pago… verificados”) and lists standard payment methods, but there is no visible login/password form in the provided HTML/OCR, suggesting it is not directly harvesting credentials in this snapshot.

The main phishing concern is the domain and branding context: it uses a generic storefront name (“ViceHub”) and a non-established domain (vicehub.store) offering a promotional “free” item tied to GTA VI. While that pattern can be used for scams (bait-and-discount, misleading value), the evidence here is insufficient to confirm phishing with certainty—there are no clear fake security alerts, brand impersonation (e.g., no PayPal/Microsoft logos or mismatched official domains), or explicit credential collection.

Conclusion: likely a low-sophistication scam storefront or unauthorized reseller rather than credential phishing; therefore the verdict leans non-phishing for credential harvesting, with medium confidence due to suspicious-domain indicators.