# mezo.today — MALICIOUS > Beware of mezo.today, an active phishing domain luring users with fake Mezo token claims. Stay informed and protected now. ## Summary PhishDestroy identifies mezo.today as a high-risk phishing domain actively targeting users under the guise of a cryptocurrency airdrop portal. Classified under generic phishing threats, this domain poses significant risk by attempting to deceive victims into disclosing sensitive information. Analysis of mezo.today reveals it resolves to IP address 172.67.144.223 and was registered via PublicDomainRegistry.com on February 21, 2026. The domain’s page title, 'Mezo Airdrop Claim Portal | Claim Mezo Tokens Now,' is crafted to lure cryptocurrency enthusiasts. Intelligence sources including AlienVault OTX and multiple security blocklists have flagged this domain, with VirusTotal indicating that 10 out of 95 security vendors detect malicious activity linked to it. Currently active, mezo.today remains a persistent threat requiring proactive mitigation. Users are advised to avoid interacting with the site and security teams should consider blocking the domain at the network level. Continuous monitoring and updating of threat intelligence feeds will help contain exposure to this phishing operation. PhishDestroy strongly recommends vigilance against such fraudulent airdrop schemes leveraging emerging crypto trends. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Page title: Mezo Airdrop Claim Portal | Claim Mezo Tokens Now ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - Country: IN - IP: 172.67.144.223 - Nameservers: ["ns1.suspended-domain.com", "ns2.suspended-domain.com"] - SSL Issuer: WE1 ## Detection Status - VirusTotal: 10 vendors flagged Vendors: ["alphaMountain.ai", "Bfore.Ai PreCrime", "Certego", "CRDF", "CyRadar", "Forcepoint ThreatSeeker", "Gridinsoft", "Kaspersky", "Lionic", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 7 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer", "Polkadot", "SEAL", "Enkrypt", "Codeesura"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019bb7f2-1efb-70dc-b1c0-262c4f8f06d3.png - PhishDestroy: https://phishdestroy.io/domain/mezo.today/ - LLM endpoint: https://phishdestroy.io/domain/mezo.today/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/mezo.today/ Last updated: 2026-03-19