The domain www-m-jojobet.vip was registered on July 26, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently active. DNS resolution points to the IPv4 address 104.21.33.96, which belongs to Cloudflare’s network and is served by the authoritative nameservers armfazh.ns.cloudflare.com and stephane.ns.cloudflare.com. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy service, indicating that at least one anti‑phishing feed has recognized it as malicious.
VirusTotal analysis shows that 4 of 91 scanned security vendors flagged the domain, providing additional corroboration of its suspicious nature. No public information about the site’s SSL certificate, HTTP response codes, or page title is presently available, and the content of the landing page has not been disclosed in the intelligence set. This lack of observable web‑layer details limits the ability to confirm the exact phishing vector or the targeted brand, but the combination of recent creation, Cloudflare hosting, blocklist presence, and multiple vendor detections strongly suggests a purposeful phishing campaign.
Defenders should immediately add www-m-jojobet.vip to their deny lists, block outbound connections to its IP address, and monitor DNS logs for any resolutions to 104.21.33.96. Network security devices should enforce URL filtering rules that reference the known blocklist entry, and endpoint protection solutions should be updated to include the domain in their threat intelligence feeds. Continuous re‑evaluation is recommended, as additional indicators such as SSL details, HTTP status, or page content may emerge, potentially revealing the specific lure or credential‑harvesting technique employed.