fidelityworkplacekj[.]click
“Log In to Fidelity NetBenefits”
Зведення доказів
Analysis of the domain fidelityworkplacekj.click indicates a recent banking‑phishing campaign targeting users of Fidelity NetBenefits. The site was registered on 21 February 2026 and quickly began serving a page titled “Log In to Fidelity NetBenefits”. Within weeks the domain appeared on a security blocklist and was subsequently taken offline, where it remains as of the report date 23 July 2026. Threat intelligence sources confirm the malicious nature: PhishDestroy reports the domain as blocked, and AlienVault OTX includes it in fourteen distinct pulses.
VirusTotal scans show fourteen of ninety‑three security vendors flagging the host, providing independent corroboration of malicious activity. The domain resolves to the IP address 43.162.124.172, which is hosted in the United States under ASN 132203, associated with a Tencent‑owned facility on Kejizhongyi Avenue. The TLS certificate presented is identified only as “E7”, offering no additional trust. The combination of a recent registration date, a brand‑specific page title, multiple vendor detections, blocklist listings, and a known hosting infrastructure points to a deliberately crafted phishing site.
Uncertainty remains regarding the exact infrastructure used to deliver the page and whether additional companion domains share the same IP. Defensive recommendations include adding fidelityworkplacekj.click and its resolving IP to deny‑list rules, monitoring for any resurgence of the domain, and applying URL filtering that blocks the associated blocklist entry. Organizations should also educate users about the authentic Fidelity NetBenefits login URL and encourage verification of TLS certificates before credential entry. Continuous monitoring of OTX and VirusTotal for new detections is advised.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenPhish | fidelityworkplacekj.click/individual/page.html |
phishing | Phishing - Fidelity Investments |
| Cloudflare DNS | fidelityworkplacekj.click |
malicious | Sinkholed |
| OpenDNS | fidelityworkplacekj.click |
phishing | Phishing Block |
| DNS0 Zero | fidelityworkplacekj.click |
malicious | Sinkholed |
| DNS4EU | fidelityworkplacekj.click |
malicious | Sinkholed |
| OpenPhish | fidelityworkplacekj.click |
phishing | Phishing - Fidelity Investments |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога