wellsfraudsupport.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of wellsfraudsupport.com
wellsfraudsupport.com appears to present itself as a Wells Fargo login or account-support page. The screenshot shows a banking-style sign-in form, Wells Fargo branding in the page title and footer, and prompts for a username and password, suggesting the site is intended to collect account credentials or simulate an online banking portal.
Based on the domain name, this site does not appear to be an official Wells Fargo domain. The combination of a newly registered domain, the use of a well-known financial brand in the page title, and a login-focused landing page may indicate an impersonation attempt rather than a legitimate customer-support property operated by the bank.
The site appears to be hosted on mainstream cloud infrastructure and uses common third-party assets for fonts and icons. That setup is technically ordinary, but it does not by itself establish legitimacy or ownership by the brand shown on the page.
Safety Assessment for wellsfraudsupport.com
This domain shows multiple high-risk indicators at the time of this scan. It was flagged by 17 out of 91 security engines, with many detections describing phishing activity and some indicating malware-related concerns. In addition, one threat database listing was present, and the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting.
The page content raises further concern because it closely imitates a major banking login experience while using a separate, recently registered domain that is only 3 days old and has no established traffic ranking. The domain name combines the words "Wells" and "fraud support," while the page title and screenshot display Wells Fargo branding and a credential-entry form. Based on available data, this resemblance may indicate a look-alike site intended to capture sensitive financial login details.
Although one malware scan reported no flagged files and only generic heuristic labels on local assets, the broader consensus from security engines and the visible impersonation pattern are stronger indicators in this case. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL certificate issued by a mainstream certificate authority, with expiry shown in late 2026. It appears to be served through Cloudflare-facing infrastructure and hosted on Render, with the server IP geolocating to San Francisco, United States. DNSSEC is enabled, which helps protect DNS integrity, and the domain uses Squarespace-managed nameservers.
These technical features are common across both legitimate and abusive sites, so they should not be treated as proof of trustworthiness. The more notable technical concern here is the very recent registration date, combined with a login page that appears to imitate a financial institution and generic malicious-object heuristics on referenced site assets.
Share your experience with this website. Was it safe? Did you encounter any issues?