fldeiltyportfolioknowledge[.]lat
“Log In to Fidelity NetBenefits”
fldeiltyportfolioknowledge.lat — Conteúdo indisponível. Representação da marca: Fidelity; Tipo de golpe: Banking Phishing. Resumo das evidências: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 92/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On 23 July 2026 analysts observed the domain fldeiltyportfolioknowledge.lat. The domain was registered on 21 February 2026 and currently resolves to the IPv4 address 43.162.112.221, which is assigned to an AS132203 network operated from a Tencent building on Kejizhongyi Avenue in the United States. The site presents the page title “Log In to Fidelity NetBenefits”, indicating an attempt to impersonate Fidelity’s NetBenefits portal. The SSL certificate presented is identified by the label “E8”, a characteristic previously associated with malicious hosting infrastructure.
The domain appears in fourteen AlienVault OTX pulses, demonstrating repeated use in threat‑intel feeds. It is listed on a single security blocklist and has been actively blocked by the PhishDestroy service. VirusTotal analysis shows fourteen of ninety‑three scanning engines flag the domain as malicious, reinforcing the suspicion of a phishing operation. The overall risk rating is elevated and the domain’s status is recorded as offline, suggesting that the hosting has been taken down or otherwise rendered inaccessible.
Evidence confirms that the domain is being used for banking‑phishing activity targeting Fidelity customers, but no additional payload or credential‑harvesting infrastructure has been publicly disclosed. The limited number of blocklist entries and the modest detection count imply that the campaign may be in an early stage or employing a low‑profile hosting strategy. Defenders should add the domain and its resolved IP address to deny‑list rules, monitor DNS queries for similar newly‑registered .lat domains, and continue to track OTX pulse updates for any emerging indicators. Ongoing verification of the SSL certificate fingerprint and periodic rescans on VirusTotal are advised to capture any changes in detection status.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo