URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · HIGH CONFIDENCE
No phishing signals detected
Risk score
0.06
6 / 100 · Low risk
URL anatomy
https
://
g
.
page
/r/CVrAgPYS9bGJEBM/review
flagged
registered domain
path
protocol / query
Why this verdict
Visual similarity to known brand
100% structural similarity to Google Maps
↑ risk
Email-auth posture (SPF/DMARC)
DMARC p=none (monitoring only) — domain can still be spoofed in mail
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
CAA issuer restriction
CAA restricts certificate issuance to: pki.goog
↓ risk
DNSSEC signing
Zone is DNSSEC-signed with a parent DS delegation anchor — origin integrity is cryptographically protected
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used:
dns
network
jarm
asn
Indicators of compromise
| URL | hxxps://g[.]page/r/CVrAgPYS9bGJEBM/review | |
| Host | g[.]page | |
| Brand | Google Maps | |
| Screenshot | https://cdn.zerophish.ai/5ef0b6e0-6414-461b-988c-27da4a68694e.jpg | |
| Scan ID | d48901de-ab0e-4d77-bca6-78c5d31ef47e |
Detection signals
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
100% structural similarity to Google Maps
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
Brand impersonation
G
Google Maps
100%
Technical profile
| Host | g.page |
| Registered domain | g.page |
| Scheme | https |
| Content length | 50498 B |
| HTTP | 200 · text/html |
| DMARC policy | p=none |
| SPF policy | permissive |
| MX records | none |
Analyst summary
Initial scan
What the page is
The page presents itself as a Google verification interstitial (“About this page”) rather than a login or payment screen. It is asking the user to solve a CAPTCHA/verification challenge to continue.
Suspicious elements checked
-
No credential collection form: The HTML includes a form with
id="captcha-form"and a reCAPTCHA widget, but there is no username/password, credit-card, or account-details form. -
No brand impersonation of another company: The content and referenced policy/support links are consistent with Google’s services (“Terms of Service” at
www.google.com/policies/terms/and “Learn more” atsupport.google.com/...). - No fake security warning claiming account compromise: While it warns about “unusual traffic” and bot behavior, it does so in a standard anti-automation context.
-
URL consistency: The URL is under
g.page/r/..., which is a Google short/listing redirect domain, and the embedded displayed URL ishttps://www.google.com/maps/place/....
Brand and domain relationship
- Identified brand: Google Maps.
-
Domain alignment: The effective destination shown in the page includes
www.google.com/maps/..., which is the legitimate domain for Google Maps content.
Verdict
Legitimate (not phishing). The page behavior matches a typical Google anti-bot/CAPTCHA check and does not attempt to harvest credentials or payment information. The phishing score is low due to the absence of form-based credential collection and the strong alignment with Google-owned domains.