URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 16 d ago. Click Reanalyze to run a fresh scan.
PHISHING · MEDIUM CONFIDENCE

Phishing detected

brand Lafise scan id 53c68668 duration signals 0 failing / 0
Risk score 0.89
89 / 100 · —
Tags
https :// .
flagged registered domain path protocol / query
URL hxxps://formulario-digital-2026-apknm[.]cr-web[.]workers[.]dev/
Brand Lafise
Screenshot https://cdn.zerophish.ai/6885d86b-27c4-440b-b1fa-37124a4f5c8b.jpg
Scan ID 53c68668-f553-412e-bbef-d83c18655db7

No detection signals on this scan — it predates the signal pipeline. Re-analyze to capture them.

Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

No technical metadata captured for this scan.

Initial scan heuristic + LLM

The website at https://formulario-digital-2026-apknm.cr-web.workers.dev/ comes off suspicious due to a number of reasons. Firstly, it impersonates a popular brand ‘Lafise’ but the domain does not match the legitimate ‘Lafise’ brand’s domain. Secondly, the texts extracted appear to be baiting users with attractive benefits and offering financial leeways in the form of tax benefits and debt forgiveness, a common bait used by phishers. Though it did not directly alert the user about a problem with their account, it indirectly uses social engineering techniques like offering unexpected rewards and displaying links for sensitive information.