The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://Fmhy[.]net | |
| Host | fmhy[.]net | |
| Screenshot | https://cdn.zerophish.ai/ccbd0f5f-1809-490e-9825-29e2fc8a5c9b.jpg | |
| Scan ID | ea7a9489-8997-476d-874e-7f569a3499d7 |
No brand impersonation signals available.
| Host | fmhy.net |
| Registered domain | fmhy.net |
| Scheme | https |
| Content length | 84815 B |
| HTTP | 200 · text/html |
| DMARC policy | p=none |
| SPF policy | soft |
| MX records | present |
The page at https://Fmhy.net presents itself as “freemediaheckyeah” (FMHY), describing a “largest collection of free stuff on the internet” with navigation to topics like Streaming, Gaming, and downloads. The visible HTML/OCR does not show any login, password, or account-verification flow.
Suspicious-phishing signals such as fake security alerts, urgency (“your account will be closed”), or credential-collection forms are not present in the provided content. The only modal text shown is an informational prompt about “Base64 Encoded Link” and suggests tools/userscripts to decode it; it does not request credentials.
The site’s branding (“FMHY” / “freemediaheckyeah”) does not appear to impersonate a specific mainstream brand like PayPal, Microsoft, or Apple, and no domain mismatch is evident from the provided URL alone.
Given the lack of credential harvesting or brand impersonation signals in the supplied HTML/OCR, this appears to be a legitimate informational/portal page rather than a phishing site. Confidence is kept low only because the analysis is limited to the provided excerpt and does not include full runtime behavior or form elements outside the captured HTML.