URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 15 d ago. Click Reanalyze to run a fresh scan.
SUSPICIOUS · LOW CONFIDENCE

Suspicious — review required

brand Orange Cash scan id ca5cf866 duration 5.51s signals 1 failing / 12
Risk score 0.22
22 / 100 · Medium risk
Tags
http :// orangecash-top . pages . dev
flagged registered domain path protocol / query
URL hxxp://orangecash-top[.]pages[.]dev
Host orangecash-top[.]pages[.]dev
Registered domain pages[.]dev
Brand Orange Cash
Screenshot https://cdn.zerophish.ai/a51e26c8-d8eb-4098-a00c-c2a3d2339bd1.jpg
Scan ID ca5cf866-6187-4a0f-b26d-896e2015833d
15 d ago
SUSPICIOUS mobimera.com safe
15 d ago
SAFE mobimera.com safe
15 d ago
SUSPICIOUS gmc-infotainment-system-reset.pages.dev safe
515 d ago
REVIEW revoke-cash-39s.pages.dev safe
521 d ago
REVIEW zerophish.pages.dev safe
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
×
SSL certificate
Served over plaintext HTTP
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render
O
Orange Cash
12%
Host orangecash-top.pages.dev
Registered domain pages.dev
Scheme http
Content length 81571 B
HTTP 200 · text/html
Initial scan heuristic + LLM

Verdict: likely legitimate information hub (low confidence)

The page presents itself as “Orange Cash - Nền tảng tổng hợp thông tin tài chính 2026” / “Blog Tổng Hợp Thông Tin” with Vietnamese navigation items (e.g., “Đánh giá ứng dụng”, “Thẻ tín dụng”). The content is primarily informational (conditions for online loans, estimated approval/disbursement times, interest/fees) and repeatedly includes disclaimers.

Suspicious social-engineering signals found

  • Implied financial offer context without providing loans directly: The site discusses loan criteria and timelines (e.g., “thời gian xét duyệt và giải ngân thường chỉ từ 15 đến 60 phút…”), which is the type of framing seen in loan lead-gen pages. However, this is not necessarily phishing.
  • Domain/path mismatch risk: The URL is orangecash-top.pages.dev, which is a third-party hosting domain (not orangecash.top). The OCR explicitly names “orangecash.top” as the reference domain, so the content may be a copy/decoy hosted elsewhere.

Credential harvesting / login

  • No password/login or credential form is present in the provided HTML/OCR. A visible checkbox-like consent exists (“Tôi đã đọc và xác nhận… / Tôi đã hiểu & Truy cập website”), but it does not appear to collect credentials.

Brand and URL relationship

  • Identified brand: Orange Cash.
  • The page references orangecash.top as the proper domain, but the actual URL used in this analysis is orangecash-top.pages.dev, suggesting it may not be the legitimate registered domain.

Why the overall conclusion is conservative

There are no direct credential-collection forms and strong disclaimers saying the site is not a lender (e.g., “KHÔNG phải là đơn vị cho vay…”, “KHÔNG trực tiếp xét duyệt, giải ngân…”). That lowers phishing likelihood. Still, the hosting-domain mismatch and “clone/copy” possibility increase risk, so confidence remains low.