URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 74 d ago. Click Reanalyze to run a fresh scan.
SAFE · LOW CONFIDENCE

No phishing signals detected

brand Unknown scan id ea7a9489 duration 14.63s signals 0 failing / 25
Risk score 0.08
8 / 100 · Low risk
Tags
https :// fmhy . net
flagged registered domain path protocol / query
!
Email-auth posture (SPF/DMARC)
DMARC p=none (monitoring only) — domain can still be spoofed in mail
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
DNSSEC signing
Zone is DNSSEC-signed with a parent DS delegation anchor — origin integrity is cryptographically protected
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://Fmhy[.]net
Host fmhy[.]net
Screenshot https://cdn.zerophish.ai/ccbd0f5f-1809-490e-9825-29e2fc8a5c9b.jpg
Scan ID ea7a9489-8997-476d-874e-7f569a3499d7
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

Host fmhy.net
Registered domain fmhy.net
Scheme https
Content length 84815 B
HTTP 200 · text/html
DMARC policy p=none
SPF policy soft
MX records present
Initial scan heuristic + LLM

The page at https://Fmhy.net presents itself as “freemediaheckyeah” (FMHY), describing a “largest collection of free stuff on the internet” with navigation to topics like Streaming, Gaming, and downloads. The visible HTML/OCR does not show any login, password, or account-verification flow.

Suspicious-phishing signals such as fake security alerts, urgency (“your account will be closed”), or credential-collection forms are not present in the provided content. The only modal text shown is an informational prompt about “Base64 Encoded Link” and suggests tools/userscripts to decode it; it does not request credentials.

The site’s branding (“FMHY” / “freemediaheckyeah”) does not appear to impersonate a specific mainstream brand like PayPal, Microsoft, or Apple, and no domain mismatch is evident from the provided URL alone.

Given the lack of credential harvesting or brand impersonation signals in the supplied HTML/OCR, this appears to be a legitimate informational/portal page rather than a phishing site. Confidence is kept low only because the analysis is limited to the provided excerpt and does not include full runtime behavior or form elements outside the captured HTML.