URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 75 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand SBI / PNB (mentioned in article) scan id 66ded0f1 duration 15.49s signals 0 failing / 15
Risk score 0.06
6 / 100 · Low risk
Tags
https :// hellobanker . in / ? p=84081
flagged registered domain path protocol / query
!
Email-auth posture (SPF/DMARC)
DMARC p=none (monitoring only) — domain can still be spoofed in mail
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://hellobanker[.]in/?p=84081
Host hellobanker[.]in
Brand SBI / PNB (mentioned in article)
Screenshot https://cdn.zerophish.ai/2262cc18-b48a-4387-a172-9bc5fa189235.jpg
Scan ID 66ded0f1-e249-4e30-b1f4-b967c6211602
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 15 ·
Captured page
screenshot · captured at scan live page render
S
SBI / PNB (mentioned in article)
5%
Host hellobanker.in
Registered domain hellobanker.in
Scheme https
Content length 214106 B
HTTP 200 · text/html
DMARC policy p=none
SPF policy none
MX records present
Initial scan heuristic + LLM

The page is a banking-news style article titled “Is SBI Merging with PNB? Here’s the Truth Behind the Viral News” on the domain hellobanker.in. The content explicitly warns readers that the viral merger claim is “not genuine” and advises them to “wait for an official announcement,” which is not typical of credential-harvesting phishing.

Suspicious phishing elements such as a login/password/OTP form, payment request, or urgent account-compromise prompts are not present in the provided HTML/OCR text. The only notable outbound actions are social links/feeds (“Join Whatsapp News Group” and “Join Telegram News Group”), which could be used for marketing or redirection, but there is no evidence here of collecting credentials.

Brand-wise, the site discusses SBI and PNB as subjects of an article, but it does not claim to be the official bank, and the URL belongs to hellobanker.in rather than a bank’s domain. Overall, the structure and messaging align with informational content rather than impersonation or scam flows.