ddfroednjfidelity[.]shop
“Log In to Fidelity NetBenefits”
ddfroednjfidelity.shop — 内容不可用. 品牌冒充:Fidelity; 诈骗类型:Banking Phishing. 证据摘要: VirusTotal 9/93 (ADMINUSLabs, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; PhishDestroy score 77/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of ddfroednjfidelity.shop as of July 24 2026 indicates the domain is a confirmed generic phishing site targeting Fidelity NetBenefits users. The domain was registered on 21 February 2026 and is currently taken offline. The page title retrieved from the site reads “Log In to Fidelity NetBenefits,” matching the declared scam type of Banking Phishing. Infrastructure observations show the domain resolves to IP 43.162.112.41, an address located in the United States and associated with ASN 132203, a Tencent‑operated network.
The TLS certificate presented is identified as grade “E7,” and the site appears on a single security blocklist. Reputation services have assigned a Gridinsoft trust score of 0 out of 100, indicating a lack of trust. The domain has been cited in thirteen AlienVault OTX threat‑intelligence pulses and is listed as blocked by PhishDestroy. VirusTotal analysis reports nine of ninety‑three scanners flagging the domain, reinforcing the malicious assessment.
The limited detection footprint—only one blocklist entry—suggests that the site may have been short‑lived or insufficiently propagated before takedown. Defenders should continue to block the domain at DNS and proxy layers, monitor for any resurgence of the same host header or similar credential‑harvesting URLs, and incorporate the IP address and TLS fingerprint into intrusion‑detection signatures. Given the recent creation date and the presence of multiple intelligence sources, any inbound traffic to this domain should be considered malicious, and affected users should be instructed to change their Fidelity credentials immediately. Ongoing vigilance is recommended, particularly for email campaigns that reference Fidelity NetBenefits login pages, as attackers may reuse the same social‑engineering template against new infrastructure.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。