MALICIOUS — CRITICAL
Is m2o.dj Safe? Phishing Analysis
m2o[.]
Analysis of the domain m2o.dj shows it was registered on May 14, 2026 and currently resolves to the IP address 135.125.204.195, hosted by OVH GmbH in Germany.
- VirusTotal
- 2/91
- Blocklists
- 2 · MetaMask, SEAL
- Availability
- Last known active · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
Evidence Analysis
Analysis of the domain m2o.dj shows it was registered on May 14, 2026 and currently resolves to the IP address 135.125.204.195, hosted by OVH GmbH in Germany. The site presents a valid HTTPS certificate issued by Let’s Encrypt (R12) and returns an HTTP 200 response, indicating an active web service. Threat intelligence sources flag the domain as a high‑risk generic phishing operation: one of ninety‑two VirusTotal scanners flagged the domain, Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on three public blocklists. It is additionally listed in an AlienVault OTX pulse and has been blocked by the PhishDestroy, MetaMask, and SEAL blocklists. The page title returned by the web server is "m2o.dj ..la DJ mail," but the actual content has not been publicly disclosed, so the specific phishing lure or credential‑capture mechanism remains unknown. Defenders should treat the domain as malicious, enforce outbound DNS filtering to block m2o.dj and its resolved IP, and consider adding the host to local blocklists. Continuous monitoring of associated IP reputation and periodic re‑scans are recommended to detect any changes in the site’s behavior or hosting infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Data coverage12 recorded checks
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
VirusTotal Analysis
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.