fidelityworkplaceef[.]click
“Log In to Fidelity NetBenefits”
证据摘要
Analysis as of July 23, 2026 indicates that the domain fidelityworkplaceef.click was registered on February 21, 2026. The site presents the page title “Log In to Fidelity NetBenefits,” suggesting an attempt to impersonate Fidelity’s employee benefits portal. The infrastructure is hosted at IP address 43.162.112.221, which belongs to AS132203 and is geolocated in the United States at a Tencent building on Kejizhongyi Avenue. The SSL certificate is identified only as “E8,” providing minimal cryptographic assurance.
The domain has been referenced in four AlienVault OTX threat intelligence pulses and is listed on at least one external blocklist. PhishDestroy has already blocked the domain, and security vendors on VirusTotal flagged it in 14 of 93 scans. Independent reputation services assign extremely low trust scores: Gridinsoft rates the domain 0 out of 100, and Scamadviser scores it 1 out of 100. The current operational status is offline, indicating that the malicious site has been taken down or is no longer responding.
While the page title and scam type (“Banking Phishing”) are confirmed, the exact phishing kit, credential harvesting method, and any associated command‑and‑control infrastructure remain unverified because no additional forensic artifacts have been published. Defenders should treat any traffic to this address as hostile. Immediate actions include updating network firewalls and proxy filters to deny DNS resolution and HTTP/S connections to 43.162.112.221, adding the domain to existing URL filtering policies, and monitoring for any residual artifacts such as emails referencing “Fidelity NetBenefits.” Continuous threat‑intel feeds should be consulted for any resurgence of the domain or related aliases, and incidents involving credential submissions to Fidelity‑related services should be investigated for possible compromise.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控