Phishing detection: mail.wellsfargoreports.com
Wells Fargo Investigate
Domain
mail.wellsfargoreports.com0 CT hosts on apex
IP
104.21.87.104
URL
https://mail.wellsfargoreports.com/user/?js_test=1
Cert
-
Phishunt analysis Beta
34
medium suspicion suspiciousheuristic risk score · not a probability
Keyword matchBrand in domain labelOpenPhish
19 signals fired · detector v2.0.0
AI analysis AIBeta
Credential harvesting
Subdomain of a freshly registered Wells Fargo impersonation domain (0 days old), displaying login-themed content and brand references to harvest banking credentials. Confirmed malicious by OpenPhish. Shares infrastructure with another phishing page on the same apex domain.
OpenPhishYoung domainLogin text in screenshot
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-05 · confidence 85%
Domain & Network
Whois
Registrar
OwnRegistrar, Inc.
Network
Country
United States
Hosting
Cloudflare, Inc.
ASN
AS13335
TLS Cert
-
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise