EN ES PT
Back to Stats

Visual Capture

Screenshot of www.mercadolibre.com.uy

Detection Info

https://www.mercadolibre.com.uy/gz/account-verification?go=https%3A%2F%2Flistado.mercadolibre.com.uy%2Fpagina%2Fstickerland%2F&tid=a8ba3f00-a713-4dfc-becf-3b17abf519e5
Detected Brand
Mercado Libre
Country
Uruguay
Confidence
100%
HTTP Status
200
Report ID
de2fcb8b-cf3…
Analyzed
2026-03-16 19:37

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T121A120E23899493E23F386DAF0A2975830CA9599C541B40CD69517FD0BD8EA6ECCD31F
CONTENT ssdeep
96:Y6aVei5DI0wVWdAXy2k8lcN3rIjfeb1GmcoGkGcGBavG61GEOG0K1GY4tVM1GYga:wsWd4yLscN51GmVGkGcGO1GEOGN1GY4I

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f326390cd986f326
VISUAL aHash
000000ffffffffff
VISUAL dHash
8c2849320c10041b
VISUAL wHash
000000fff0f0f1ff
VISUAL colorHash
07e00000000
VISUAL cropResistant
8c2849320c10041b

Code Analysis

Risk Score 79/100
Threat Level BAJO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Impersonation
• Target: Mercado Libre users
• Method: Mimicking login page
• Exfil: Unknown
• Indicators: Matching branding and language, but no forms in this image
• Risk: Low

🔒 Obfuscation Detected

  • atob
  • unescape
  • base64_strings

🎯 Kit Endpoints

  • https://www.mercadolibre.com/jms/mlu/lgz/login?platform_id=ml&go=https://listado.mercadolibre.com.uy/pagina/stickerland/&loginType=negative_traffic

📡 API Calls Detected

  • PUT
  • inPrivate
  • POST

📊 Risk Score Breakdown

Total Risk Score
25/100

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Mercado Libre users (Uruguay)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
HIGH - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 4 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Mercado Libre
Official Website
www.mercadolibre.com.uy

⚔️ Attack Methodology

Primary Method: Impersonation

The attacker creates a web page that looks like the Mercado Libre login page to steal credentials.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
www.mercadolibre.com.uy
Registered
None
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.