# m.berachainbuild.xyz — MALICIOUS > m.berachainbuild.xyz impersonates Berachain with medium risk. Active on multiple blocklists. Stay alert and avoid this suspicious domain. ## Summary PhishDestroy categorizes m.berachainbuild.xyz as a medium-risk brand impersonation threat targeting Berachain. This domain poses a significant risk by exploiting Berachain's brand reputation. The domain, created on February 21, 2026, resolves to IP 104.75.88.77 and is flagged by 8 out of 95 security vendors on VirusTotal. It also appears on three security blocklists, confirming its malicious intent. The page title closely mimics the legitimate brand name, attempting to deceive users. Currently active, users are advised to avoid interaction with m.berachainbuild.xyz. Organizations should implement domain filtering and monitor DNS queries to block access to this domain and protect their assets. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Target brand: Berachain - Page title: berachainbuild.xyz ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 104.75.88.77 - SSL Issuer: Go Daddy Secure Certificate Authority - G2 ## Detection Status - VirusTotal: 8 vendors flagged Vendors: ["ADMINUSLabs", "BitDefender", "CyRadar", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Google Safebrowsing", "Sophos"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/0199e398-4376-748f-9bc3-59b686526cc3.png - PhishDestroy: https://phishdestroy.io/domain/m.berachainbuild.xyz/ - LLM endpoint: https://phishdestroy.io/domain/m.berachainbuild.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/m.berachainbuild.xyz/ Last updated: 2026-03-19