Ok I know this is SUPER late, but I kinda think what they've done is kinda clever. They have https:// on their domain and make a point on the webpage to "only trust webpages with https://". Additionally, they also encoded their html in hex, so you can't immediately tell what's going on behind...