URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 63 d ago. Click Reanalyze to run a fresh scan.
SUSPICIOUS · LOW CONFIDENCE

Suspicious — review required

brand AceImg scan id ed454dfc duration 10.53s signals 1 failing / 25
Risk score 0.22
22 / 100 · Medium risk
Tags
https :// aceimg . com /upload/ ? f=LX0D26VJc.mp4
flagged registered domain path protocol / query
×
Email-auth posture (SPF/DMARC)
No DMARC record — domain trivially spoofable in phishing email
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "aceimg" reads as pronounceable / brand-like (randomness 40%)
↓ risk
enrichment used: dns network jarm asn
URL hxxps://aceimg[.]com/upload/?f=LX0D26VJc[.]mp4
Host aceimg[.]com
Brand AceImg
Screenshot https://cdn.zerophish.ai/acaca52e-8aa8-45f0-8804-f4e15f0fa2d6.jpg
Scan ID ed454dfc-337d-419f-8cf6-a9ccd5f5859c
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
AceImg
5%
Host aceimg.com
Registered domain aceimg.com
Scheme https
Content length 57045 B
HTTP 200 · text/html
DMARC policy none
SPF policy soft
MX records present
Initial scan heuristic + LLM

What the page is presenting

The page identifies itself as AceImg (title: “AceImg - Free and Simple File Sharing”) and shows a minimal file-sharing UI with an “Upload” link. The only prominent call-to-action is a link labeled “Click here to unlock now”.

Suspicious elements found

  • Third-party “unlock” link (potentially deceptive/redirect behavior): The page contains a single conspicuous external anchor:
    • href="https://ey43.com/4/10567623" with text “Click here to unlock now”. This is a common phishing pattern: an “unlock”/paywalled/restricted-content prompt that sends users to an off-site destination. However, the provided HTML does not include any credential collection fields or account-warning content.

Brand and URL relationship

  • Identified brand: AceImg (site name shown in the DOM and OCR: “aceimg”).
  • URL domain: aceimg.com matches the presented brand (no obvious domain-brand mismatch like a fake PayPal domain).
  • No evidence of impersonating a major brand (e.g., PayPal/Microsoft) in the provided content.

Verdict reasoning (phishing vs. legitimate)

Based on the provided HTML/OCR, the page does not include a login form, password/credential harvesting fields, or fake security/account warnings. The main risk signal is the off-site “unlock now” redirect to ey43.com, which could be used for scam flows, but there isn’t enough evidence here to confirm phishing. Therefore, this is more likely not a credential-harvesting phishing page, but the external redirect keeps confidence low.

Conclusion

Likely legitimate page shell with a suspicious external “unlock now” link, not clearly phishing from the supplied content.