The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://shikapesa[.]com/ | |
| Host | shikapesa[.]com | |
| Brand | ShikaPesa | |
| Screenshot | https://cdn.zerophish.ai/42de6bad-9937-4dad-bb30-faffa92fb1b6.jpg | |
| Scan ID | e8db10f7-b2e2-479b-9b17-dc130da5e9f5 |
|
34 d ago
|
SAFE | shikapesa.com | safe |
| Host | shikapesa.com |
| Registered domain | shikapesa.com |
| Scheme | https |
| Content length | 106621 B |
| HTTP | 200 · text/html |
| DMARC policy | p=quarantine |
| SPF policy | strict |
| MX records | present |
The page presents itself as “ShikaPesa Trade Gurus” at https://shikapesa.com/, focusing on trading/binary-style features (e.g., “Predict direction. Win up to ×5.0”) and displaying a prominent “DEMO”/“Demo mode — practising with virtual KES. No real money, no risk.” banner.
Suspicious phishing signals are limited in the provided HTML/text: there is no visible credential-collection form on this page (only navigation links like “Login” and “Sign Up”), and there are no fake security alerts, account-freeze warnings, or urgent “act now” prompts in the captured content. The “System: CONGRATULATIONS @… on withdrawal …” feed is a marketing-style social proof element, but it does not directly request credentials or imitate a major brand.
Because this is not impersonating a well-known brand (the domain is the brand’s own: shikapesa.com) and no credential form is shown, the phishing likelihood is low-to-moderate; however, the presence of a trading platform with “withdrawal” messaging means the real risk would depend on the hidden Login/withdrawal pages not provided here.