URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 29 d ago. Click Reanalyze to run a fresh scan.
SUSPICIOUS · LOW CONFIDENCE

Suspicious — review required

brand Flipkart scan id d711097e duration 16.33s signals 1 failing / 25
Risk score 0.22
22 / 100 · Medium risk
Tags
https :// fkrt . store /share/9au0sei
flagged registered domain path protocol / query
×
Email-auth posture (SPF/DMARC)
No DMARC record — domain trivially spoofable in phishing email
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://fkrt[.]store/share/9au0sei
Host fkrt[.]store
Brand Flipkart
Screenshot https://cdn.zerophish.ai/41d3d4a2-9f58-468d-96df-6685031dc7d0.jpg
Scan ID d711097e-0b17-49d2-830a-161c141c23ff
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
F
Flipkart
10%
Host fkrt.store
Registered domain fkrt.store
Scheme https
Content length 841633 B
HTTP 200 · text/html
DMARC policy none
SPF policy none
MX records none
Initial scan heuristic + LLM

Assessment

Based on the provided URL and the visible content, the page appears to be a product listing for a “Purepet Lavender Fragrance (For Multiple Cat) - 5kg Pet Litter Tray Refill” on a Flipkart-like storefront.

Suspicious elements / phishing signals

  • Brand/URL mismatch: The URL is on an unrelated domain (fkrt.store) while the page content and title reference Flipkart.com (e.g., the HTML title contains “Flipkart.com” and the OCR shows extensive “Flipkart” navigation like “Login”, “Cart”, “Flipkart Assured”, and “Flipkart Internet Private Limited”). This is a common phishing pattern (legitimate-looking brand content hosted on an attacker-controlled domain).
  • Potential domain typo/name: fkrt.store resembles an abbreviation of Flipkart, which can indicate impersonation.

Non-suspicious elements (legitimacy indicators)

  • No credential collection visible: In the simplified HTML/OCR, there is no visible password/login form or account credential harvesting UI—only navigation text like “Login”.
  • No payment/OTP prompt shown: The OCR shows typical ecommerce elements (“Delivery details”, “Add to cart”, “Buy now”, prices, returns, and company/legal sections) but no explicit request for credentials or one-time codes.

Verdict

I lean legitimate/low-risk because the provided excerpt does not show an actual login/credential form or explicit scam workflow, but the brand-to-domain mismatch is significant enough that confidence cannot be high.

Confidence

Low: evidence is limited to a single rendered excerpt; if the full page includes a working login form, redirects, or hidden scripts, the phishing likelihood could be higher.