The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
Suspicious — review required
| URL | hxxp://orangecash-top[.]pages[.]dev | |
| Host | orangecash-top[.]pages[.]dev | |
| Registered domain | pages[.]dev | |
| Brand | Orange Cash | |
| Screenshot | https://cdn.zerophish.ai/a51e26c8-d8eb-4098-a00c-c2a3d2339bd1.jpg | |
| Scan ID | ca5cf866-6187-4a0f-b26d-896e2015833d |
|
15 d ago
|
SUSPICIOUS | mobimera.com | safe |
|
15 d ago
|
SAFE | mobimera.com | safe |
|
15 d ago
|
SUSPICIOUS | gmc-infotainment-system-reset.pages.dev | safe |
|
515 d ago
|
REVIEW | revoke-cash-39s.pages.dev | safe |
|
521 d ago
|
REVIEW | zerophish.pages.dev | safe |
| Host | orangecash-top.pages.dev |
| Registered domain | pages.dev |
| Scheme | http |
| Content length | 81571 B |
| HTTP | 200 · text/html |
Verdict: likely legitimate information hub (low confidence)
The page presents itself as “Orange Cash - Nền tảng tổng hợp thông tin tài chính 2026” / “Blog Tổng Hợp Thông Tin” with Vietnamese navigation items (e.g., “Đánh giá ứng dụng”, “Thẻ tín dụng”). The content is primarily informational (conditions for online loans, estimated approval/disbursement times, interest/fees) and repeatedly includes disclaimers.
Suspicious social-engineering signals found
- Implied financial offer context without providing loans directly: The site discusses loan criteria and timelines (e.g., “thời gian xét duyệt và giải ngân thường chỉ từ 15 đến 60 phút…”), which is the type of framing seen in loan lead-gen pages. However, this is not necessarily phishing.
-
Domain/path mismatch risk: The URL is
orangecash-top.pages.dev, which is a third-party hosting domain (notorangecash.top). The OCR explicitly names “orangecash.top” as the reference domain, so the content may be a copy/decoy hosted elsewhere.
Credential harvesting / login
- No password/login or credential form is present in the provided HTML/OCR. A visible checkbox-like consent exists (“Tôi đã đọc và xác nhận… / Tôi đã hiểu & Truy cập website”), but it does not appear to collect credentials.
Brand and URL relationship
- Identified brand: Orange Cash.
- The page references orangecash.top as the proper domain, but the actual URL used in this analysis is orangecash-top.pages.dev, suggesting it may not be the legitimate registered domain.
Why the overall conclusion is conservative
There are no direct credential-collection forms and strong disclaimers saying the site is not a lender (e.g., “KHÔNG phải là đơn vị cho vay…”, “KHÔNG trực tiếp xét duyệt, giải ngân…”). That lowers phishing likelihood. Still, the hosting-domain mismatch and “clone/copy” possibility increase risk, so confidence remains low.