URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 34 d ago. Click Reanalyze to run a fresh scan.
SAFE · MEDIUM CONFIDENCE

No phishing signals detected

brand ShikaPesa scan id fe4f9cac duration 10.07s signals 0 failing / 25
Risk score 0.18
18 / 100 · Low risk
Tags
https :// shikapesa . com /
flagged registered domain path protocol / query
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "shikapesa" reads as pronounceable / brand-like (randomness 26%)
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=quarantine — domain is protected against direct spoofing
↓ risk
CAA issuer restriction
CAA restricts certificate issuance to: letsencrypt.org
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://shikapesa[.]com/
Host shikapesa[.]com
Brand ShikaPesa
Screenshot https://cdn.zerophish.ai/e115d3c7-31ba-46e0-a5f6-9a57331185f0.jpg
Scan ID fe4f9cac-8b1e-4dcc-9186-45879aa8602a
34 d ago
SAFE shikapesa.com safe
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
S
ShikaPesa
15%
Host shikapesa.com
Registered domain shikapesa.com
Scheme https
Content length 106621 B
HTTP 200 · text/html
DMARC policy p=quarantine
SPF policy strict
MX records present
Initial scan heuristic + LLM

The page at https://shikapesa.com/ presents itself as “ShikaPesa Trade Gurus” offering a crypto trading interface (e.g., “BTC/KES Binary”, “Predict direction. Win up to ×5.0”) with a visible “DEMO”/“Demo mode — practising with virtual KES. No real money, no risk” banner. It contains links to “Login” and “Sign Up” but, in the provided simplified HTML/OCR snippet, there is no displayed password/credential input form for harvesting.

Suspicious phishing patterns are limited here: there are no fake security alerts, no urgent account-closure warnings, and no external-brand impersonation (the only brand-like text is the site’s own “ShikaPesa”). The “System: CONGRATULATIONS … on withdrawal …” messages and celebratory emoji could indicate social-engineering style “proof of withdrawals,” but they are not coupled with credential collection on this specific view.

Because the domain matches the brand name shown (“shikapesa.com” → ShikaPesa) and the page appears to be a self-contained trading/demonstration landing view without an on-page login form, the evidence leans legitimate, though confidence is not high due to the presence of a login flow elsewhere (not shown) and generic “withdrawal” hype content.