🚨 CYBERSECURITY ALERT
Attention, WhatsApp users and Mercado Livre customers: scam is circulating with the promise of “R$ 300 Mother’s Day gift.” The message “Achei que era fake 😂 mas eu realmente recebi R$ 300, testa aí” is a classic phishing lure.
I conducted a thorough technical analysis with information pivots and cross-checks across multiple reliable sources. Result: 100% fraud. Do not click. Do not share.
1/5 – INDICATORS OF COMPROMISE (IOCs)
•Domain:
rgrky.buzz
•Registration date: 02/11/2025 (only 6 months old – data updated on 02/05/2026)
•WHOIS: hidden
•Registrar: NameSilo (commonly used in mass fraud campaigns)
•Hosting: Cloudflare (IP shared with dozens of suspicious domains)
•SSL Certificate: Google Trust Services (valid until 30/07/2026) – Domain Validated (anyone can obtain)
•Tracking parameter: ?s=wa& = “shared via WhatsApp” (enables commission payment to promoters)
•Typical path: /xctmLmkY/br-pt?... (random code Brazilian Portuguese language)
2/5 – REPUTATION CROSS-CHECK (verified sources)
•
SiteConfiavel.com.br (updated 02/05/2026): site registered 6 months ago, SSL active, zero complaints on Reclame Aqui (standard for new domains used in scams). Explicit high-risk alert.
•
urlquery.net: identical URLs on the same domain (e.g.,
rgrky.buzz/SfrNGJ/…?s=wa) already classified as malicious/sinkholed.
•VirusTotal and Scamadviser: low reputation, extremely recent registration, and high-risk registrar.
•Official Mercado Livre: never sends random links via WhatsApp promising free Pix or “gifts.”
3/5 – INFORMATION PIVOTS USED IN THE INVESTIGATION
1Extraction of domain, path, and parameters from the received link.
2WHOIS query registrar history → identification of Brazilian campaign usage pattern.
3Reverse search for path /xctmLmkY ?s=wa → dozens of identical “Mother’s Day” scam variations.
4Cross-check against official Mercado Livre communications → complete absence of any legitimate partnership or campaign.
5Analysis of message text → exact copy used in thousands of similar scams.
4/5 – HOW THE SCAM WORKS
The fake page mimics Mercado Livre and requests “redeem,” status sharing, or personal data (CPF, phone, email). In later stages, it may demand a “release fee,” steal credentials, or install malware. The supposed “receipts” are fake social proof created by paid promoters (R$ 10–50 per victim).
5/5 – CONCLUSION AND RECOMMENDATIONS
This is a professional phishing operation exploiting commemorative dates to create urgency and false social proof.
Immediate recommended action:
•Block and report the contact as spam on WhatsApp.
•If you have clicked or provided data: change passwords, enable two-factor authentication, monitor bank and Pix statements, and consider preventive CPF freeze.
Report to:
• Mercado Livre app → Help → Report scam
• Federal Police or your state’s Cybercrime Division
Share this thread to protect your network. Prevention is the best defense.
#CybersecurityAlert #Phishing #ScamWarning #MercadoLivre #OSINT #MothersDayScam #DigitalSecurity #WhatsAppFraud #StayVigilant
(Source:
SiteConfiavel.com.br,
urlquery.net, VirusTotal and public OSINT pivots