beadpie[.]xyz
“beadpie.xyz”
Evidence Summary
Analysis of beadpie.xyz shows a recent domain registration (July 15 2025) through Namecheap Inc. The authoritative name servers are brad.ns.cloudflare.com and emma.ns.cloudflare.com, indicating use of Cloudflare’s DNS service. DNS resolution points to IP address 188.114.97.3, a host commonly associated with Cloudflare‑provided edge nodes. The domain appears on one public security blocklist and has been actively blocked by the PhishDestroy sinkhole, confirming that threat‑mitigation operators have observed malicious activity. VirusTotal reports that 10 of 91 scanned security vendors flag the domain, reinforcing the suspicion of abuse.
The threat type is cataloged as generic phishing, and the current operational status is listed as active. Concrete evidence therefore includes the blocklist entry, the PhishDestroy block, and the multi‑vendor detection count. No public SSL certificate details, HTTP response codes, page title, or additional reputation scores are presently disclosed, leaving those aspects unverified. The lack of a Safe Browsing or OTX entry in the supplied data does not imply absence of detection but simply that the information was not provided.
Defenders should continue to deny network communications to 188.114.97.3 and add beadpie.xyz to local deny lists. Monitoring of Cloudflare‑associated IP ranges for similar domains is advisable, as is periodic re‑query of VirusTotal and other reputation services for updated detection counts. Because the domain is only one year old yet already flagged by multiple sources, organizations should treat any email or web request referencing beadpie.xyz as high‑risk until a thorough content analysis can be performed.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive