wilobank.evlink11.net
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of wilobank.evlink11.net
This domain appears to host a Spanish-language login page branded as "Wilobank," with fields for username/email and password, a remember-me toggle, and a password recovery link. The page title, "Wilobank : Iniciar sesión," and the screenshot indicate that the site is presenting itself as an account-access portal rather than a general informational website.
Based on the visible content and linked resources, the page may be intended to collect user credentials for a banking or financial-service style account. It is hosted on a subdomain of evlink11.net rather than on a primary Wilobank-branded domain, which is an unusual setup for a financial login portal and may warrant additional scrutiny.
The operator is not clearly identified in the provided scan data. While some referenced assets point to domains containing "wilobank-mail," the scanned page itself does not provide enough ownership or corporate information to independently verify that it is operated by the legitimate brand it appears to reference.
Safety Assessment for wilobank.evlink11.net
The scan results indicate elevated risk signals at the time of this scan. The domain was flagged by 10 out of 91 security engines, with multiple detections describing the page as phishing or malicious. In addition, the visible content is a credential-entry form for a financial-looking brand, and the domain name uses a third-party parent domain rather than what users might expect for an official banking login page. That combination may be consistent with credential-harvesting activity.
Other signals were mixed. The malware scan reported a generic suspicious finding on the main page, but blacklist and threat-database checks were otherwise clean at the time of this scan, and the domain itself is not newly registered. Even so, clean blacklist status does not outweigh a multi-engine phishing consensus when the page is actively requesting login details.
Based on these findings, this website may pose potential risks to visitors, particularly if they are asked to enter account credentials or other sensitive information.
Technical Description
The site was reachable over HTTPS with a valid SSL/TLS certificate issued by Google Trust Services, expiring in October 2026. It appears to be proxied through Cloudflare, with hosting on IP address 104.18.13.240 and nameservers set to Cloudflare infrastructure. The server location was reported as Toronto, Canada.
From a domain-configuration perspective, the domain is about 8 years old and registered through GoDaddy, which may reduce the likelihood of a throwaway registration but does not by itself validate the legitimacy of this specific subdomain. DNSSEC appears to be unsigned, and the page is hosted on a subdomain of evlink11.net rather than a clearly official financial domain, which may be a notable trust concern for a login portal.
Share your experience with this website. Was it safe? Did you encounter any issues?