portal.finarraywealth.com
Kategoria: Phishing
Aby korzystać z produktu z pełną funkcjonalnością, musisz kupić licencję na Combo Cleaner. Dostępny jest ograniczony siedmiodniowy bezpłatny okres próbny. Combo Cleaner należy do RCS LT i jest obsługiwany przez tę firmę, spółkę macierzystą PCRisk.com.
Opis portal.finarraywealth.com
portal.finarraywealth.com appears to be a customer login portal for FinArray Wealth Private Limited, a financial-services business referenced on the page. The screenshot shows a branded sign-in interface titled "Finarray Login" with mobile-number OTP access, along with contact details, company registration information, and links to privacy and disclaimer pages on the parent domain finarraywealth.com.
Based on the domain structure and page content, this subdomain likely serves as an account-access area for clients or leads rather than a public marketing homepage. The site presents itself as being associated with wealth or financial data services, and the available classification data also places it in the financial-services space, although some security sources additionally classify it as phishing.
Ocena bezpieczeństwa portal.finarraywealth.com
This website raises notable concerns based on available scan data. At the time of this scan, 8 out of 91 security engines flagged the domain, with multiple scanners classifying it as phishing or malicious, while several web-classification sources associated it with phishing, fraud, or financial services. That combination suggests the site may be involved in credential collection or deceptive financial-themed activity, even though the page visually presents itself as a branded login portal.
At the same time, the malware scan did not identify malicious files, and blacklist checks were clean at the time of review. That means no active malware payloads were detected in the scanned files, but a clean file scan does not rule out phishing risk, especially for a login page requesting account or OTP-related information. The lack of broad blacklist coverage may also reflect the point-in-time nature of these checks.
Because this is a financial login page and several security engines flagged it for phishing-related concerns, visitors should treat it with caution and independently verify that the portal is genuinely operated by the expected organization before entering personal information. Based on these findings, this website may pose potential risks to visitors.
Opis techniczny
The site uses a valid Let's Encrypt SSL certificate expiring in June 2026 and is hosted on AWS EC2 in the us-west-2 region, with Apache/2.4.58 serving the content. The domain is about four years old, uses GoDaddy nameservers, and DNSSEC appears to be unsigned. The page loads common third-party assets such as Bootstrap, Font Awesome, and Google Fonts, and no flagged external links or iframes were identified in the provided scan data.
A technical concern is the reported server stack showing OpenSSL 1.0.2k-fips, which is an older branch and may indicate legacy cryptographic components on the server side. While this alone does not confirm compromise, the combination of an older software stack, a financial login workflow, no Tranco ranking, and multiple phishing-related detections increases the need for caution and independent verification.
Podziel się swoimi doświadczeniami z tą witryną. Czy była bezpieczna? Czy wystąpiły jakieś problemy?