The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://shikapesa[.]com/ | |
| Host | shikapesa[.]com | |
| Brand | ShikaPesa | |
| Screenshot | https://cdn.zerophish.ai/e115d3c7-31ba-46e0-a5f6-9a57331185f0.jpg | |
| Scan ID | fe4f9cac-8b1e-4dcc-9186-45879aa8602a |
|
34 d ago
|
SAFE | shikapesa.com | safe |
| Host | shikapesa.com |
| Registered domain | shikapesa.com |
| Scheme | https |
| Content length | 106621 B |
| HTTP | 200 · text/html |
| DMARC policy | p=quarantine |
| SPF policy | strict |
| MX records | present |
The page at https://shikapesa.com/ presents itself as “ShikaPesa Trade Gurus” offering a crypto trading interface (e.g., “BTC/KES Binary”, “Predict direction. Win up to ×5.0”) with a visible “DEMO”/“Demo mode — practising with virtual KES. No real money, no risk” banner. It contains links to “Login” and “Sign Up” but, in the provided simplified HTML/OCR snippet, there is no displayed password/credential input form for harvesting.
Suspicious phishing patterns are limited here: there are no fake security alerts, no urgent account-closure warnings, and no external-brand impersonation (the only brand-like text is the site’s own “ShikaPesa”). The “System: CONGRATULATIONS … on withdrawal …” messages and celebratory emoji could indicate social-engineering style “proof of withdrawals,” but they are not coupled with credential collection on this specific view.
Because the domain matches the brand name shown (“shikapesa.com” → ShikaPesa) and the page appears to be a self-contained trading/demonstration landing view without an on-page login form, the evidence leans legitimate, though confidence is not high due to the presence of a login flow elsewhere (not shown) and generic “withdrawal” hype content.