fldeiltyportfolioknowledge[.]lat
“Log In to Fidelity NetBenefits”
fldeiltyportfolioknowledge.lat — Контент недоступен. Олицетворение бренда: Fidelity; Тип мошенничества: Banking Phishing. Сводка доказательств: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 92/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On 23 July 2026 analysts observed the domain fldeiltyportfolioknowledge.lat. The domain was registered on 21 February 2026 and currently resolves to the IPv4 address 43.162.112.221, which is assigned to an AS132203 network operated from a Tencent building on Kejizhongyi Avenue in the United States. The site presents the page title “Log In to Fidelity NetBenefits”, indicating an attempt to impersonate Fidelity’s NetBenefits portal. The SSL certificate presented is identified by the label “E8”, a characteristic previously associated with malicious hosting infrastructure.
The domain appears in fourteen AlienVault OTX pulses, demonstrating repeated use in threat‑intel feeds. It is listed on a single security blocklist and has been actively blocked by the PhishDestroy service. VirusTotal analysis shows fourteen of ninety‑three scanning engines flag the domain as malicious, reinforcing the suspicion of a phishing operation. The overall risk rating is elevated and the domain’s status is recorded as offline, suggesting that the hosting has been taken down or otherwise rendered inaccessible.
Evidence confirms that the domain is being used for banking‑phishing activity targeting Fidelity customers, but no additional payload or credential‑harvesting infrastructure has been publicly disclosed. The limited number of blocklist entries and the modest detection count imply that the campaign may be in an early stage or employing a low‑profile hosting strategy. Defenders should add the domain and its resolved IP address to deny‑list rules, monitor DNS queries for similar newly‑registered .lat domains, and continue to track OTX pulse updates for any emerging indicators. Ongoing verification of the SSL certificate fingerprint and periodic rescans on VirusTotal are advised to capture any changes in detection status.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание