# demo.berachainbuild.xyz — MALICIOUS > demo.berachainbuild.xyz flagged for phishing risk. Domain now offline but previously targeted users with deceptive tactics. Stay informed. ## Summary PhishDestroy identifies demo.berachainbuild.xyz as a domain involved in generic phishing attacks that pose a medium-level risk to users. Phishing remains a critical threat as it aims to trick victims into divulging sensitive information, potentially leading to identity theft or financial loss. The presence of this domain on multiple security blocklists underscores the ongoing attempts to exploit unsuspecting users. Investigations reveal that demo.berachainbuild.xyz was registered on February 21, 2026, but is currently offline. Despite this, the domain appeared on three different security blocklists and was flagged by eight security vendors on VirusTotal, signaling a credible threat during its active period. The domain was registered through a dead domain registrar, which is often associated with less reputable registrations. Its takedown limits immediate risk but vigilance remains essential. Users are advised to remain cautious when encountering unfamiliar URLs, especially those resembling legitimate services but with suspicious domains like demo.berachainbuild.xyz. Avoid clicking on unsolicited links or providing personal details unless the source is verified. Organizations should update their blocklists to include this domain and educate personnel on recognizing phishing attempts to reduce the risk of compromise. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Target brand: Berachain - Page title: berachainbuild.xyz ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 23.56.162.17 - SSL Issuer: Go Daddy Secure Certificate Authority - G2 ## Detection Status - VirusTotal: 8 vendors flagged Vendors: ["ADMINUSLabs", "BitDefender", "CyRadar", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Google Safebrowsing", "Sophos"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/0199e39a-1533-7453-a35c-754798f99ae3.png - PhishDestroy: https://phishdestroy.io/domain/demo.berachainbuild.xyz/ - LLM endpoint: https://phishdestroy.io/domain/demo.berachainbuild.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/demo.berachainbuild.xyz/ Last updated: 2026-03-19