URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 33 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand "" scan id 76abf30f duration 11.3s signals 1 failing / 25
Risk score 0.05
5 / 100 · Low risk
Tags
https :// one . dosugbarkrg . com /
flagged registered domain path protocol / query
×
Email-auth posture (SPF/DMARC)
No DMARC record — domain trivially spoofable in phishing email
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "dosugbarkrg" reads as pronounceable / brand-like (randomness 37%)
↓ risk
enrichment used: dns network jarm asn
URL hxxps://one[.]dosugbarkrg[.]com/
Host one[.]dosugbarkrg[.]com
Registered domain dosugbarkrg[.]com
Brand ""
Screenshot https://cdn.zerophish.ai/005f720a-4727-4d44-96d8-cd132b1bd38b.jpg
Scan ID 76abf30f-f813-4f4d-92ad-41d1652c52a5
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
"
""
0%
Host one.dosugbarkrg.com
Registered domain dosugbarkrg.com
Scheme https
Content length 280157 B
HTTP 200 · text/html
DMARC policy none
SPF policy none
MX records none
Initial scan heuristic + LLM

What the page is presenting itself as

The page appears to be a Russian adult-services directory for “Проститутки Кургана” (sex work listings in Kurgan), branded as “DOSUGBAR / DOS GBAR,” with many user-generated profiles showing prices, phone numbers, and reviews.

Suspicious elements found (phishing-focused)

  • No credential harvesting form in the provided HTML. The only visible authentication UI is a “Войти” (Log in) label, but the simplified HTML snippet does not include an actual username/password input form or submission endpoint tied to credential collection.
  • No fake payment/security warning patterns. There are no UI elements resembling “your account has been compromised,” “verify to avoid closure,” or “urgent action required.”
  • Brand/URL relationship: The domain one.dosugbarkrg.com matches the on-page branding “DOSUGBAR” and does not mimic a third-party brand like PayPal, Microsoft, or banks.

Why phishing is unlikely

Phishing sites commonly include credential submission forms, urgency/security scare messages, or impersonation of a well-known brand with a mismatched domain. In the given URL + HTML/OCR, the content is consistent with an adult directory/listing site, and the suspicious phishing indicators are absent.

Verdict

Legitimate (with caveats): While the site content is clearly adult-oriented and may involve privacy/safety risks typical of such platforms, the specific phishing indicators (credential-collection form harvesting, brand impersonation, fake security warnings) are not evidenced in the provided material.