wellsfargoverify.net
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of wellsfargoverify.net
The domain wellsfargoverify.net appears to present itself as a Wells Fargo account-security or account-verification page. Based on the domain name, page title, and screenshot, the site is designed to mimic a banking security alert workflow and asks visitors to enter a username, password, and a 6-digit code under an "Account Limited" message.
The content shown does not appear to be an independent informational page about Wells Fargo. Instead, it closely imitates the branding and login-related messaging of the financial institution, including references to unusual activity, secure connection claims, and links pointing to legitimate Wells Fargo resources. Based on available data, the site may be intended to capture sensitive banking credentials from users who believe they are interacting with the real bank.
Safety Assessment for wellsfargoverify.net
This domain shows multiple high-risk indicators at the time of this scan. It was flagged by 21 out of 89 security engines, and a major threat database listed it for social-engineering activity. The screenshot also shows a credential-harvesting style form requesting a username, password, and one-time code while using Wells Fargo branding, which is commonly associated with phishing attempts.
Additional context increases concern: the domain is only 3 days old, has no established traffic ranking, and its name closely resembles the Wells Fargo brand while adding the word "verify," which may indicate a look-alike site rather than an official banking domain. Although the malware scan did not detect malicious files at the time of analysis, that does not offset the stronger phishing signals from multi-engine detections, blacklist listings, and the page content itself. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal on its own but adds minor caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid Let's Encrypt certificate, hosted on GitHub infrastructure at IP address 185.199.110.153 in San Francisco, United States. The web server appears to be GitHub.com, and the domain uses Cloudflare nameservers. DNSSEC is unsigned, which is not uncommon but does mean DNS responses do not appear to have DNSSEC validation.
From a security-analysis perspective, the presence of valid SSL/TLS should not be treated as proof of legitimacy. In this case, the combination of a newly registered domain, brand-resembling naming, hosting on a general-purpose platform, and a banking-style credential form are stronger indicators of abuse than the certificate status.
Share your experience with this website. Was it safe? Did you encounter any issues?