portal.finarraywealth[.]com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of portal.finarraywealth[.]com
portal.finarraywealth[.]com appears to be a customer login portal for FinArray Wealth Private Limited, a financial-services business referenced on the page. The screenshot shows a branded sign-in interface titled "Finarray Login" with mobile-number OTP access, along with contact details, company registration information, and links to privacy and disclaimer pages on the parent domain finarraywealth.com.
Based on the domain structure and page content, this subdomain likely serves as an account-access area for clients or leads rather than a public marketing homepage. The site presents itself as being associated with wealth or financial data services, and the available classification data also places it in the financial-services space, although some security sources additionally classify it as phishing.
Safety Assessment for portal.finarraywealth[.]com
This website raises notable concerns based on available scan data. At the time of this scan, 8 out of 91 security engines flagged the domain, with multiple scanners classifying it as phishing or malicious, while several web-classification sources associated it with phishing, fraud, or financial services. That combination suggests the site may be involved in credential collection or deceptive financial-themed activity, even though the page visually presents itself as a branded login portal.
At the same time, the malware scan did not identify malicious files, and blacklist checks were clean at the time of review. That means no active malware payloads were detected in the scanned files, but a clean file scan does not rule out phishing risk, especially for a login page requesting account or OTP-related information. The lack of broad blacklist coverage may also reflect the point-in-time nature of these checks.
Because this is a financial login page and several security engines flagged it for phishing-related concerns, visitors should treat it with caution and independently verify that the portal is genuinely operated by the expected organization before entering personal information. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring in June 2026 and is hosted on AWS EC2 in the us-west-2 region, with Apache/2.4.58 serving the content. The domain is about four years old, uses GoDaddy nameservers, and DNSSEC appears to be unsigned. The page loads common third-party assets such as Bootstrap, Font Awesome, and Google Fonts, and no flagged external links or iframes were identified in the provided scan data.
A technical concern is the reported server stack showing OpenSSL 1.0.2k-fips, which is an older branch and may indicate legacy cryptographic components on the server side. While this alone does not confirm compromise, the combination of an older software stack, a financial login workflow, no Tranco ranking, and multiple phishing-related detections increases the need for caution and independent verification.
Share your experience with this website. Was it safe? Did you encounter any issues?