URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 11 d ago. Click Reanalyze to run a fresh scan.
SAFE · LOW CONFIDENCE

No phishing signals detected

brand Nemonicon scan id a20febb2 duration 11.32s signals 1 failing / 12
Risk score 0.15
15 / 100 · Low risk
Tags
https :// nemonicon . com
flagged registered domain path protocol / query
URL hxxps://nemonicon[.]com
Host nemonicon[.]com
Brand Nemonicon
Screenshot https://cdn.zerophish.ai/845b4a6e-f280-47ab-9afa-86c59e74d019.jpg
Scan ID a20febb2-f3ac-4301-ad26-931b964385c5
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
×
Credential collection form
Credential collection form detected on the page
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render
N
Nemonicon
5%
Host nemonicon.com
Registered domain nemonicon.com
Scheme https
Content length 107302 B
HTTP 200 · text/html
JARM 7939b39b37937938c29629628c260286f3d82c0d5f5c56c1c29a72a8aa219f
Redirect hops 2
Initial scan heuristic + LLM

The page at https://nemonicon.com presents itself as the corporate website for “Nemonicon GmbH” offering Swiss IT services for “Cloud, Security und KI,” including sections like “Unsere Leistungen,” “Microsoft Partner,” and contact/location information.

Suspicious phishing signals are not prominent: there are no visible urgent security warnings, account-takeover messaging, or login/password harvesting flows. The primary form-related element appears to be a legitimate contact request (“Jetzt Beratung anfragen” / “Nachricht senden” with fields “Name, E-Mail, Unternehmen, Nachricht”), which is a normal lead-capture pattern rather than credential collection.

The URL domain matches the displayed brand name (Nemonicon), and the content branding is internally consistent. Because the provided HTML/OCR does not clearly show any password/credential field, phishing is unlikely; however, confidence is set to low because only a simplified snippet is provided and the form behavior (e.g., action/fields) isn’t fully verifiable from the text alone.