URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 88 d ago. Click Reanalyze to run a fresh scan.
SUSPICIOUS · LOW CONFIDENCE

Suspicious — review required

brand Unknown scan id 50485df8 duration 12.37s signals 0 failing / 12
Risk score 0.20
20 / 100 · Medium risk
Tags
https :// xyera . buzz /LWaxmf/gh-en ? 0615270884740025066&s=wa&
flagged registered domain path protocol / query
URL hxxps://xyera[.]buzz/LWaxmf/gh-en?0615270884740025066&s=wa&
Host xyera[.]buzz
Screenshot https://cdn.zerophish.ai/9d2d1aca-7f85-4e49-bf73-8b282cf21c0e.jpg
Scan ID 50485df8-6229-4bd8-862b-172f1a98f967
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

Host xyera.buzz
Registered domain xyera.buzz
Scheme https
Content length 39040 B
HTTP 200 · text/html
JARM 0d39b39b30d30d37d20320327d20122de7c02fe862e334985aa656e5df0651
Redirect hops 1
Initial scan heuristic + LLM

The page content appears to be a generic “404” message (“404codeaaadx43kp8lx405n8ytf8o”) with no visible login/checkout form, branding, or account-related prompts.

The provided URL is on a non-brand domain (“xyera.buzz”), which is commonly seen in phishing, but there is insufficient evidence in the supplied HTML/OCR to conclude this specific page is impersonating a known service.

Because the page lacks credential collection elements and any brand cues, the safest assessment with the given data is inconclusive/low-confidence rather than a definite phishing page.