The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://bittli[.]in/R49W5lxo | |
| Host | bittli[.]in | |
| Screenshot | https://cdn.zerophish.ai/141d6537-4ac8-4cbf-a0f9-101c6e6e3ea6.jpg | |
| Scan ID | 80dd9628-91f9-4e5d-9581-2b161f4c9d43 |
|
24 d ago
|
SAFE | bittli.in | safe |
No brand impersonation signals available.
| Host | bittli.in |
| Registered domain | bittli.in |
| Scheme | https |
| Content length | 39013 B |
| HTTP | 200 · text/html |
| DMARC policy | none |
| SPF policy | none |
| MX records | present |
Analysis summary
The provided content is effectively empty: the HTML only shows a simple “OK” message, and the OCR text also contains “OK”. There are no visible login pages, forms, branding, links, or warnings to evaluate.
Signals checked
- Credential collection / login form: Not present. No password/email fields or submission controls were included in the provided HTML.
- Fake security warnings / urgency cues: None found beyond the literal text “OK”.
- Brand impersonation / mismatch: No brand elements or logos identified; therefore no domain/brand verification is possible.
- Suspicious redirects / external references: None shown in the provided HTML.
URL vs. brand
The URL is https://bittli.in/R49W5lxo. Since no brand is presented in the available content, there is no basis to confirm or deny alignment with a specific legitimate provider.
Verdict
With the current evidence, the safest assessment is likely legitimate / indeterminate due to lack of phishing indicators. Confidence is low because the page content is too minimal to conclusively rule out phishing (e.g., the real content may not be included in the simplified HTML/OCR).