The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
Suspicious — review required
| URL | hxxps://aceimg[.]com/upload/?f=LX0D26VJc[.]mp4 | |
| Host | aceimg[.]com | |
| Brand | AceImg | |
| Screenshot | https://cdn.zerophish.ai/acaca52e-8aa8-45f0-8804-f4e15f0fa2d6.jpg | |
| Scan ID | ed454dfc-337d-419f-8cf6-a9ccd5f5859c |
| Host | aceimg.com |
| Registered domain | aceimg.com |
| Scheme | https |
| Content length | 57045 B |
| HTTP | 200 · text/html |
| DMARC policy | none |
| SPF policy | soft |
| MX records | present |
What the page is presenting
The page identifies itself as AceImg (title: “AceImg - Free and Simple File Sharing”) and shows a minimal file-sharing UI with an “Upload” link. The only prominent call-to-action is a link labeled “Click here to unlock now”.
Suspicious elements found
-
Third-party “unlock” link (potentially deceptive/redirect behavior): The page contains a single conspicuous external anchor:
-
href="https://ey43.com/4/10567623"with text “Click here to unlock now”. This is a common phishing pattern: an “unlock”/paywalled/restricted-content prompt that sends users to an off-site destination. However, the provided HTML does not include any credential collection fields or account-warning content.
-
Brand and URL relationship
- Identified brand: AceImg (site name shown in the DOM and OCR: “aceimg”).
-
URL domain:
aceimg.commatches the presented brand (no obvious domain-brand mismatch like a fake PayPal domain). - No evidence of impersonating a major brand (e.g., PayPal/Microsoft) in the provided content.
Verdict reasoning (phishing vs. legitimate)
Based on the provided HTML/OCR, the page does not include a login form, password/credential harvesting fields, or fake security/account warnings. The main risk signal is the off-site “unlock now” redirect to ey43.com, which could be used for scam flows, but there isn’t enough evidence here to confirm phishing. Therefore, this is more likely not a credential-harvesting phishing page, but the external redirect keeps confidence low.
Conclusion
Likely legitimate page shell with a suspicious external “unlock now” link, not clearly phishing from the supplied content.