MALICIOUS — CRITICAL
fidelitysing[.]cyou
Analysis indicates that the domain fidelitysing.cyou was registered on 21 February 2026 and is currently taken offline.
- VirusTotal
- 15/93
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fidelitysing.cyou — Контент недоступний (HTTP 502). Уособлення бренду: Fidelity; Тип шахрайства: Banking Phishing. Зведення доказів: VirusTotal 15/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 5 alerts; URLScan malicious verdict; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
fidelitysing.cyou — Banking Phishing Report
Analysis indicates that the domain fidelitysing.cyou was registered on 21 February 2026 and is currently taken offline.
Analysis indicates that the domain fidelitysing.cyou was registered on 21 February 2026 and is currently taken offline. DNS resolution points to the IPv4 address 43.162.109.70, which is announced by AS132203 and appears to be hosted in the United States within a Tencent data center. The TLS certificate presented by the host is rated E8, suggesting a low‑trust certificate. The only visible page title retrieved during the scan is “Log In to Fidelity NetBenefits”, aligning with the listed scam type of Banking Phishing.
VirusTotal has recorded 15 positive detections out of 93 submitted scanners, confirming that multiple anti‑malware engines consider the domain malicious. The same domain is present on one external blocklist and has been listed in fourteen AlienVault OTX pulses, indicating that the broader threat‑intel community has observed activity related to this indicator. PhishDestroy has also added the domain to its blocklist, reinforcing its classification as a phishing vector. Defenders should immediately deny any outbound or inbound traffic to fidelitysing.cyou and the associated IP address 43.162.109.70 at the network perimeter.
The domain should be added to URL filtering and email security policies, and any existing logs should be queried for prior connections or credential submissions. Because the site is currently offline, continuous monitoring of the IP range and the registrar for re‑registration attempts is advisable. Correlation of the E8 certificate fingerprint with other observed phishing kits may reveal additional infrastructure reuse. Finally, security teams should update threat‑intel feeds with the observed indicators (domain, IP, TLS fingerprint, and detection counts) to improve early warning for future campaigns that may reuse the same hosting environment.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenPhish | fidelitysing.cyou/plan/page.html |
phishing | Phishing - Fidelity Investments |
| OpenDNS | fidelitysing.cyou |
phishing | Phishing Block |
| Cloudflare DNS | fidelitysing.cyou |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | fidelitysing.cyou |
malicious | Sinkholed |
| DNS0 Zero | fidelitysing.cyou |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.