URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 514 d ago. Click Reanalyze to run a fresh scan.
PHISHING · MEDIUM CONFIDENCE

Phishing detected

brand Booking.com scan id 98111c5a duration signals 0 failing / 0
Risk score 0.85
85 / 100 · —
Tags
https :// .
flagged registered domain path protocol / query
URL hxxps://reserves-page[.]com/evquyjaw
Brand Booking.com
Screenshot https://cdn.zerophish.ai/f47cb311-2ed6-4e40-a72b-111def6c6daa.jpg
Scan ID 98111c5a-09a3-4dc6-b69a-3c54f41490df

No detection signals on this scan — it predates the signal pipeline. Re-analyze to capture them.

Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

No technical metadata captured for this scan.

Initial scan heuristic + LLM

The site is almost certainly a phishing site. The URL does not match the legitimate domain for ‘Booking.com’. It also tries to create a sense of urgency with the message ‘Limited supply for your dates:’, alongside attempting to harvest personal information through forms. It specifically targeted at customers of ‘Booking.com’. The last observation is classic social engineering techniques often used in phishing attacks. There were also multiple none-matching brand references in the HTML like ‘Hotel Venezia’, indicating a higher phishing_score.