# PhishDestroy threat dossier — gratisbrasil.com.br ================================================================ Fetched: 2026-07-30 13:37:36 UTC Canonical: https://phishdestroy.io/domain/gratisbrasil.com.br/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Generic Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 17/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Netcraft, SOCRadar, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 82.112.247.150 (BR, São Paulo) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger Registered: 2026-04-12 Page title: Delivery online via WhatsApp integrado com Mercadopago. HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-06-13 Status: INVALID chain Fingerprint: ca93db1bb67655715fa033cd08fc939ed58e1b67eb1d8cbfb9dbcd2ed97a7684 Subject Alternative Names (related infrastructure — often same operator): - www.gratisbrasil.com.br ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-12 17:30:04 UTC (by PhishDestroy tracker) First reported: 2026-06-15 06:36:23 UTC (abuse notice filed) Last verified: 2026-07-30 12:21:00 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-07 21:55:28 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] gratisbrasil.com.br: Fake WhatsApp-MercadoPago phishing site This domain is flagged for elevated-risk generic phishing activity targeting Brazilian e-commerce users. Analysis indicates the infrastructure was specifically designed to mimic legitimate WhatsApp-MercadoPago integration for delivery services, as evidenced by the page title 'Delivery online via WhatsApp integrado com Mercadopago.' The threat primarily involves credential harvesting and unauthorized financial transactions through fake payment portals. Infrastructure analysis reveals the domain gratisbrasil.com.br was registered on April 12, 2026, through an undisclosed registrar. It resolves to IP address 82.112.247.150, hosted in Brazil by a provider known for shared hosting environments. The domain appears on one security blocklist and is currently blocked by at least one threat intelligence feed. VirusTotal detection metrics show 13 out of 95 security vendors flagging the domain as malicious, with a Let's Encrypt R13 SSL certificate providing superficial legitimacy. The domain was operational for a limited period before being taken offline. Mitigation for this specific threat type involves several technical measures. Network administrators should implement DNS-based blocking for 82.112.247.150 and the gratisbrasil.com.br domain across all organizational endpoints. Users who may have interacted with the site should immediately revoke any MercadoPago API credentials or payment authorizations, as these are primary targets of the phishing scheme. Financial institutions should monitor for unusual transaction patterns originating from devices that visited this IP address during the active period. Organizations should also conduct security awareness training focusing on WhatsApp-integrated payment scams, particularly those targeting delivery services in Brazil. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: c5088e888c97ad440a61d247596f88e5 TLS cert SHA-256: ca93db1bb67655715fa033cd08fc939ed58e1b67eb1d8cbfb9dbcd2ed97a7684 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/gratisbrasil.com.br/ JSON API: https://api.destroy.tools/v1/check?domain=gratisbrasil.com.br Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,828 domains (83,526 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io