URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 34 d ago. Click Reanalyze to run a fresh scan.
SAFE · MEDIUM CONFIDENCE

No phishing signals detected

brand ShikaPesa scan id e8db10f7 duration 8.46s signals 0 failing / 25
Risk score 0.18
18 / 100 · Low risk
Tags
https :// shikapesa . com /
flagged registered domain path protocol / query
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "shikapesa" reads as pronounceable / brand-like (randomness 26%)
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=quarantine — domain is protected against direct spoofing
↓ risk
CAA issuer restriction
CAA restricts certificate issuance to: letsencrypt.org
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://shikapesa[.]com/
Host shikapesa[.]com
Brand ShikaPesa
Screenshot https://cdn.zerophish.ai/42de6bad-9937-4dad-bb30-faffa92fb1b6.jpg
Scan ID e8db10f7-b2e2-479b-9b17-dc130da5e9f5
34 d ago
SAFE shikapesa.com safe
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
S
ShikaPesa
5%
Host shikapesa.com
Registered domain shikapesa.com
Scheme https
Content length 106621 B
HTTP 200 · text/html
DMARC policy p=quarantine
SPF policy strict
MX records present
Initial scan heuristic + LLM

The page presents itself as “ShikaPesa Trade Gurus” at https://shikapesa.com/, focusing on trading/binary-style features (e.g., “Predict direction. Win up to ×5.0”) and displaying a prominent “DEMO”/“Demo mode — practising with virtual KES. No real money, no risk.” banner.

Suspicious phishing signals are limited in the provided HTML/text: there is no visible credential-collection form on this page (only navigation links like “Login” and “Sign Up”), and there are no fake security alerts, account-freeze warnings, or urgent “act now” prompts in the captured content. The “System: CONGRATULATIONS @… on withdrawal …” feed is a marketing-style social proof element, but it does not directly request credentials or imitate a major brand.

Because this is not impersonating a well-known brand (the domain is the brand’s own: shikapesa.com) and no credential form is shown, the phishing likelihood is low-to-moderate; however, the presence of a trading platform with “withdrawal” messaging means the real risk would depend on the hidden Login/withdrawal pages not provided here.