The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
Suspicious — review required
| URL | hxxps://vicehub[.]store | |
| Host | vicehub[.]store | |
| Screenshot | https://cdn.zerophish.ai/5a5444be-5ffb-44c1-8d5b-7418f257d896.jpg | |
| Scan ID | 4f060ebf-9cd2-4360-8c7a-6d51b41407a7 |
No brand impersonation signals available.
| Host | vicehub.store |
| Registered domain | vicehub.store |
| Scheme | https |
| Content length | 443712 B |
| HTTP | 200 · text/html |
| DMARC policy | p=none |
| SPF policy | soft |
| MX records | present |
The page presents itself as a game pre-order store (“Reserva GTA VI Ultimate Edition + LED Vice City Gratis”) with urgency and social proof (“⚠️ UNIDADES LIMITADAS”, “Opiniones verificadas”, countdown timer). It includes multiple claims of safety and legitimacy (“Pago 100% seguro”, “Métodos de pago… verificados”) and lists standard payment methods, but there is no visible login/password form in the provided HTML/OCR, suggesting it is not directly harvesting credentials in this snapshot.
The main phishing concern is the domain and branding context: it uses a generic storefront name (“ViceHub”) and a non-established domain (vicehub.store) offering a promotional “free” item tied to GTA VI. While that pattern can be used for scams (bait-and-discount, misleading value), the evidence here is insufficient to confirm phishing with certainty—there are no clear fake security alerts, brand impersonation (e.g., no PayPal/Microsoft logos or mismatched official domains), or explicit credential collection.
Conclusion: likely a low-sophistication scam storefront or unauthorized reseller rather than credential phishing; therefore the verdict leans non-phishing for credential harvesting, with medium confidence due to suspicious-domain indicators.