Security Scan Report: mepi.com.sa

Site favicon
Submitted: Oct 4, 2026, 12:33:55 PMCompleted: Oct 4, 2026, 12:35:17 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Compromised MEPICO plastics site serving an injected ClickFix/FileFix fake 'Microsoft verify' overlay that copies a shell command to the clipboard; CRITICAL YARA, IDS and threat-intel all confirm malware distribution.

Risk Factors (5)
ClickFix/FileFix clipboard-injection kit injected into the page (fake human-verification prompt with paste-and-run instructions)
Impersonates Microsoft account security / SmartScreen in the fake verification overlay on a non-Microsoft domain
Critical network IDS alerts for EtherHiding malware exfiltration and a known ClickFix distribution domain
Third-party malicious exploit-kit/clearfake domains contacted by page scripts
Primary domain mepi.com.sa flagged as a malware 'unknown loader' in threat intelligence (single source)
Domain age information unavailable

Details

Page Title

MEPICO | Plastic Raw Materials Supplier & Manufacturer

Scan Type

public

Domain Name Analysis

The domain 'mepi.com.sa' uses the Saudi country-code top-level domain (.com.sa) while skipping any subdomain. Its registrable label 'mepi' stretches across 4 characters holding two vowels versus 2 consonants. Splitting it apart reveals 2 words: mep, i. Expect two characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mepi.com.sa

Page Load Overview

14.50s
Total Load Time
3.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,741 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software73% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
73%
e-commerce shopping
62%
social media network
58%
documentation technical
53%
government public service
52%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13162.241.219.65Phoenix, Arizona, United States
AS31898Oracle Corporation
5142.251.14.97Google · CDNUnited States
AS15169Google LLC
5216.239.34.36Google · CDNUnited States
AS15169Google LLC
5142.251.110.95Google · CDNUnited States
AS15169Google LLC
5172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5172.66.146.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
5104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.110.94Google · CDNUnited States
AS15169Google LLC
12323--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T199944AE2B6F5222D0056B482D935FF9D345AAC51D501C3BABFBC16CBF780670932AB64

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:+fd0PoDKHqedFqEPMFzEQHTwjvTLJPvMFzeQHPnQ+CsS0HHL5Tn1gAxKJTKbrv0:5vqEPMFvHTavTLJPvMF1HPQ+CH0L5TnQ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:433033:RhIAiiGTvkW7GAQGkEARmI0BJhgsAiqJQoUSmQSxCRA1DWIAScABAA+ICQSQZAAGAGG2AkYJAQ0kABADrPxAZzGETCCBQjAb

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffff000000ffffff
Perceptual Hash:991de6ee11e51319
Difference Hash:2636fafa7838260f
Wavelet Hash:ff0f0000000fffff
Color Hash:#e06c6c

Scan History

Scan history not available

Unable to load historical scan data