The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://hellobanker[.]in/?p=84081 | |
| Host | hellobanker[.]in | |
| Brand | SBI / PNB (mentioned in article) | |
| Screenshot | https://cdn.zerophish.ai/2262cc18-b48a-4387-a172-9bc5fa189235.jpg | |
| Scan ID | 66ded0f1-e249-4e30-b1f4-b967c6211602 |
| Host | hellobanker.in |
| Registered domain | hellobanker.in |
| Scheme | https |
| Content length | 214106 B |
| HTTP | 200 · text/html |
| DMARC policy | p=none |
| SPF policy | none |
| MX records | present |
The page is a banking-news style article titled “Is SBI Merging with PNB? Here’s the Truth Behind the Viral News” on the domain hellobanker.in. The content explicitly warns readers that the viral merger claim is “not genuine” and advises them to “wait for an official announcement,” which is not typical of credential-harvesting phishing.
Suspicious phishing elements such as a login/password/OTP form, payment request, or urgent account-compromise prompts are not present in the provided HTML/OCR text. The only notable outbound actions are social links/feeds (“Join Whatsapp News Group” and “Join Telegram News Group”), which could be used for marketing or redirection, but there is no evidence here of collecting credentials.
Brand-wise, the site discusses SBI and PNB as subjects of an article, but it does not claim to be the official bank, and the URL belongs to hellobanker.in rather than a bank’s domain. Overall, the structure and messaging align with informational content rather than impersonation or scam flows.