URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 24 d ago. Click Reanalyze to run a fresh scan.
SAFE · LOW CONFIDENCE

No phishing signals detected

brand Unknown scan id 80dd9628 duration 8.3s signals 1 failing / 25
Risk score 0.05
5 / 100 · Low risk
Tags
https :// bittli . in /R49W5lxo
flagged registered domain path protocol / query
×
Email-auth posture (SPF/DMARC)
No DMARC record — domain trivially spoofable in phishing email
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "bittli" reads as pronounceable / brand-like (randomness 19%)
↓ risk
enrichment used: dns jarm asn
URL hxxps://bittli[.]in/R49W5lxo
Host bittli[.]in
Screenshot https://cdn.zerophish.ai/141d6537-4ac8-4cbf-a0f9-101c6e6e3ea6.jpg
Scan ID 80dd9628-91f9-4e5d-9581-2b161f4c9d43
24 d ago
SAFE bittli.in safe
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

Host bittli.in
Registered domain bittli.in
Scheme https
Content length 39013 B
HTTP 200 · text/html
DMARC policy none
SPF policy none
MX records present
Initial scan heuristic + LLM

Analysis summary

The provided content is effectively empty: the HTML only shows a simple “OK” message, and the OCR text also contains “OK”. There are no visible login pages, forms, branding, links, or warnings to evaluate.

Signals checked

  • Credential collection / login form: Not present. No password/email fields or submission controls were included in the provided HTML.
  • Fake security warnings / urgency cues: None found beyond the literal text “OK”.
  • Brand impersonation / mismatch: No brand elements or logos identified; therefore no domain/brand verification is possible.
  • Suspicious redirects / external references: None shown in the provided HTML.

URL vs. brand

The URL is https://bittli.in/R49W5lxo. Since no brand is presented in the available content, there is no basis to confirm or deny alignment with a specific legitimate provider.

Verdict

With the current evidence, the safest assessment is likely legitimate / indeterminate due to lack of phishing indicators. Confidence is low because the page content is too minimal to conclusively rule out phishing (e.g., the real content may not be included in the simplified HTML/OCR).