The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
Suspicious — review required
| URL | hxxps://fkrt[.]store/share/9au0sei | |
| Host | fkrt[.]store | |
| Brand | Flipkart | |
| Screenshot | https://cdn.zerophish.ai/41d3d4a2-9f58-468d-96df-6685031dc7d0.jpg | |
| Scan ID | d711097e-0b17-49d2-830a-161c141c23ff |
| Host | fkrt.store |
| Registered domain | fkrt.store |
| Scheme | https |
| Content length | 841633 B |
| HTTP | 200 · text/html |
| DMARC policy | none |
| SPF policy | none |
| MX records | none |
Assessment
Based on the provided URL and the visible content, the page appears to be a product listing for a “Purepet Lavender Fragrance (For Multiple Cat) - 5kg Pet Litter Tray Refill” on a Flipkart-like storefront.
Suspicious elements / phishing signals
-
Brand/URL mismatch: The URL is on an unrelated domain (
fkrt.store) while the page content and title reference Flipkart.com (e.g., the HTML title contains “Flipkart.com” and the OCR shows extensive “Flipkart” navigation like “Login”, “Cart”, “Flipkart Assured”, and “Flipkart Internet Private Limited”). This is a common phishing pattern (legitimate-looking brand content hosted on an attacker-controlled domain). -
Potential domain typo/name:
fkrt.storeresembles an abbreviation of Flipkart, which can indicate impersonation.
Non-suspicious elements (legitimacy indicators)
- No credential collection visible: In the simplified HTML/OCR, there is no visible password/login form or account credential harvesting UI—only navigation text like “Login”.
- No payment/OTP prompt shown: The OCR shows typical ecommerce elements (“Delivery details”, “Add to cart”, “Buy now”, prices, returns, and company/legal sections) but no explicit request for credentials or one-time codes.
Verdict
I lean legitimate/low-risk because the provided excerpt does not show an actual login/credential form or explicit scam workflow, but the brand-to-domain mismatch is significant enough that confidence cannot be high.
Confidence
Low: evidence is limited to a single rendered excerpt; if the full page includes a working login form, redirects, or hidden scripts, the phishing likelihood could be higher.