The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
Suspicious — review required
| URL | hxxps://xyera[.]buzz/LWaxmf/gh-en?0615270884740025066&s=wa& | |
| Host | xyera[.]buzz | |
| Screenshot | https://cdn.zerophish.ai/9d2d1aca-7f85-4e49-bf73-8b282cf21c0e.jpg | |
| Scan ID | 50485df8-6229-4bd8-862b-172f1a98f967 |
No brand impersonation signals available.
| Host | xyera.buzz |
| Registered domain | xyera.buzz |
| Scheme | https |
| Content length | 39040 B |
| HTTP | 200 · text/html |
| JARM | 0d39b39b30d30d37d20320327d20122de7c02fe862e334985aa656e5df0651 |
| Redirect hops | 1 |
The page content appears to be a generic “404” message (“404codeaaadx43kp8lx405n8ytf8o”) with no visible login/checkout form, branding, or account-related prompts.
The provided URL is on a non-brand domain (“xyera.buzz”), which is commonly seen in phishing, but there is insufficient evidence in the supplied HTML/OCR to conclude this specific page is impersonating a known service.
Because the page lacks credential collection elements and any brand cues, the safest assessment with the given data is inconclusive/low-confidence rather than a definite phishing page.