Analysis of the domain beradrome.pro indicates it is under investigation as a potential phishing threat. Registered on July 24, 2026, through Fewmoretaps OU d/b/a Trustname.com, the domain currently resolves to the IP address 186.2.175.35. Infrastructure analysis reveals the use of nameservers ns1.anycastdns.cz and ns2.anycastdns.cz, a configuration often observed in domains associated with malicious activity due to its resilience and anonymity features. As of July 28, 2026, the domain appears on one security blocklist, specifically PhishDestroy, which suggests preliminary detection by at least one vendor specializing in phishing threats.
No detections were recorded by the 91 vendors that scanned the domain on VirusTotal, though the absence of flags does not confirm safety. The domain remains active, and its content has not been fully analyzed to determine the specific brand or service it may be impersonating. The registration age of four days, combined with its presence on a phishing-focused blocklist, raises concerns about its legitimacy.
Defenders are advised to monitor network traffic for connections to 186.2.175.35 and the domain beradrome.pro, particularly in environments where credential harvesting poses a high risk. Further investigation, including sandbox analysis or manual inspection of the site’s content, is recommended to classify the threat accurately. Organizations should consider preemptive blocking of this domain if phishing campaigns are a known risk vector.