Skip to security report
Checked Aug 9, 2026 Ref B52F064E

MALICIOUS — CRITICAL

Is m2o.dj Safe? Phishing Analysis

m2o[.]dj

Analysis of the domain m2o.dj shows it was registered on May 14, 2026 and currently resolves to the IP address 135.125.204.195, hosted by OVH GmbH in Germany.

83/100 evidence score · Critical
VirusTotal
2/91
Blocklists
2 · MetaMask, SEAL
Availability
Last known active · HTTP 200
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 2. Public blocklists reporting a match: 2. Exercise extreme caution — do not enter credentials or personal information.
Jump to section

Evidence Analysis

Ref B52F064E

Analysis of the domain m2o.dj shows it was registered on May 14, 2026 and currently resolves to the IP address 135.125.204.195, hosted by OVH GmbH in Germany. The site presents a valid HTTPS certificate issued by Let’s Encrypt (R12) and returns an HTTP 200 response, indicating an active web service. Threat intelligence sources flag the domain as a high‑risk generic phishing operation: one of ninety‑two VirusTotal scanners flagged the domain, Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on three public blocklists. It is additionally listed in an AlienVault OTX pulse and has been blocked by the PhishDestroy, MetaMask, and SEAL blocklists. The page title returned by the web server is "m2o.dj ..la DJ mail," but the actual content has not been publicly disclosed, so the specific phishing lure or credential‑capture mechanism remains unknown. Defenders should treat the domain as malicious, enforce outbound DNS filtering to block m2o.dj and its resolved IP, and consider adding the host to local blocklists. Continuous monitoring of associated IP reputation and periodic re‑scans are recommended to detect any changes in the site’s behavior or hosting infrastructure.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
2 det.
OTX references
TLS Certificate
Expired or unverified -18d
Age
3 mo New
Observed status
Last known active 200
PhishDestroy
DestroyList
Listed
Data coverage12 recorded checks
VirusTotal 2 / 91 URLQuery not checked PhishStats not checked OTX 1 community reference CF Radar no data URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS Expired or unverified WHOIS 3 mo old Screenshot not captured Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
7/9
Threat Ingested
m2o.dj detected and queued for full analysis
Jun 15, 2026
VirusTotal
2/91 recorded on VirusTotal
Aug 5, 2026
Google Safe Browsing
May 15, 2026
Blocklist Detection
Found in 2 blocklists: MetaMask, SEAL
Aug 9, 2026
OTX Community References
1 community publication reference on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
May 15, 2026
Technical Analysis Recorded
The report contains stored technology or forensic-analysis results.
Aug 9, 2026
Complaint Draft Available
No submission is recorded. You can create a draft, review it, and submit it yourself to the appropriate authority.
DestroyList Published
Jun 15, 2026
Monitoring Continues
The domain remains reachable or access-restricted; future checks may update this observation.

Public Blocklist Status

Domain Intelligence

Domain
Server / ASN Apache · AS16276 OVH SAS
IP Reputation abuse score 0/100 0 reports checked Jul 13, 2026
IP Address 135.125.204.195 DE
GeoDE Limburg an der Lahn, DE
NetworkAS16276 · OVH GmbH
RegistrationCreated May 14, 2026 (86d · New)
HTTP Status200
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 15, 2026
TLS Fingerprint
TLS Observationvalid from Apr 24, 2026scanned May 19, 2026
TLS SAN Domainswww.m2o.dj
Favicon Hash
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

2 / 91 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
CRDF
Gridinsoft
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself
Embed This ReportRead-only HTML widget
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/m2o.dj"
  title="PhishDestroy threat report for m2o.dj"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>