URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · LOW CONFIDENCE
No phishing signals detected
Risk score
0.05
5 / 100 · Low risk
URL anatomy
https
://
bittli
.
in
/Cg6uWmqn
flagged
registered domain
path
protocol / query
Why this verdict
Email-auth posture (SPF/DMARC)
No DMARC record — domain trivially spoofable in phishing email
↑ risk
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "bittli" reads as pronounceable / brand-like (randomness 19%)
↓ risk
enrichment used:
dns
jarm
asn
Indicators of compromise
| URL | hxxps://bittli[.]in/Cg6uWmqn | |
| Host | bittli[.]in | |
| Screenshot | https://cdn.zerophish.ai/5dd13658-17d9-4f57-8706-bb705fc383b3.jpg | |
| Scan ID | f7c3f7a3-659d-4682-9d28-ef01efad3153 |
Related detections
|
24 d ago
|
SAFE | bittli.in | safe |
Detection signals
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
Brand impersonation
No brand impersonation signals available.
Technical profile
| Host | bittli.in |
| Registered domain | bittli.in |
| Scheme | https |
| Content length | 39013 B |
| HTTP | 200 · text/html |
| DMARC policy | none |
| SPF policy | none |
| MX records | present |
Analyst summary
Initial scan
No meaningful phishing indicators are present in the provided content.
-
Page content: The HTML body only contains a simple text node:
OK. The OCR output is also justOK, with no login form, password/credential fields, links, or security/urgency messaging. -
Branding/URL: The URL
https://bittli.in/Cg6uWmqndoes not present any brand impersonation in the available markup/text; there is also no visible brand name to match against. - Credential collection: No forms or input fields appear in the provided HTML snippet.
Because the input appears to be an incomplete/placeholder response rather than an actual interactive page, there isn’t enough evidence to label it as phishing. With limited data, the conservative assessment is likely legitimate / indeterminate but not enough to flag phishing.