fidelityworkplaceq[.]qpon
“Log In to Fidelity NetBenefits”
fidelityworkplaceq.qpon — Contenu indisponible. Usurpation de l'identité de la marque : Fidelity; Type d'arnaque : Banking Phishing. Résumé des preuves: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLScan malicious verdict; PhishDestroy score 100/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
PhishDestroy has identified a dangerous phishing domain, fidelityworkplaceq.qpon, which specifically impersonates Fidelity Investments to steal NetBenefits login credentials. This threat is classified as a generic phishing attack, elevated risk, and has been taken offline. The domain was created on February 21, 2026, and despite its short lifespan, it managed to appear on two security blocklists and was flagged by 18 out of 95 VirusTotal security vendors, indicating widespread recognition as malicious. The domain resolves to IP address 74.48.108.25 and its SSL certificate is rated E7, a low-grade certificate often used by fraudulent sites. AlienVault OTX recorded this domain in 14 distinct threat intelligence pulses, further confirming its malicious nature.
The phishing page was titled "Log In to Fidelity NetBenefits," designed to deceive users into entering sensitive account information. The domain's registration through an unknown registrar and its recent creation date are typical red flags for phishing campaigns. PhishDestroy's analysis confirms that the site is now offline, but the threat remains significant due to potential data breaches that may have occurred while it was active. The elevated risk level is justified by the high number of security vendor flags and the brand impersonation of a major financial institution.
Users who may have interacted with this domain should immediately change their Fidelity NetBenefits passwords and enable two-factor authentication. PhishDestroy recommends monitoring account statements for unauthorized activity and reporting any suspicious login attempts to Fidelity's security team. Organizations should update their web filters to block this domain and educate employees about phishing tactics that mimic trusted financial portals. Continuous vigilance is essential, as similar domains may appear under different top-level domains or with slight variations in the domain name.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ZONE SHORTDOT · PREUVES PUBLIQUES
.qpon
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif