This cluster centers on 2764 connected domains tagged as BeaverTail, Kaiji, fbf543. 645 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1132 phone numbers (7638857447, 8664372914, 2157987305) with 10266 FTC complaints; 146 companies (JPMORGAN CHASE & CO., Advanced Resolution Services Inc., EVERBANK, NATIONAL ASSOCIATION) with 8616274 CFPB complaints; 298 email addresses (xxxxxxxxxxxxxxxxxxxxxxxx@vm...
(415) 320-1147
Last reported Mar 28, 2026
- 15 community reports from users
Campaign Intelligence
This cluster centers on 3287 connected domains tagged as HijackLoader, RemcosRAT, screenconnect. 617 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1649 phone numbers (5408463620, 8552597377, 8007873903) with 7110 FTC complaints; 143 companies (Informative LLC, HomePlus Corporation, Doral Capital Corporation) with 8547081 CFPB complaints; 807 email addresses (kellymoore_64@yahoo.com, schantzsybg7@...
This cluster centers on 2874 connected domains tagged as QuasarRAT, StealitStealer, pw-k53mv9bc. 652 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1375 phone numbers (2157987305, 2025069230, 2028641298) with 14635 FTC complaints; 160 companies (JPMORGAN CHASE & CO., Advanced Resolution Services Inc., EVERBANK, NATIONAL ASSOCIATION) with 8680419 CFPB complaints; 299 email addresses (abuse@fb.com, ...
This cluster centers on 1486 connected domains tagged as None, keylogger. 5 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1364 phone numbers (3124141737, 3163966869, 8553892999) with 17909 FTC complaints; 170 companies (EQUIFAX, INC., TRANSUNION INTERMEDIATE HOLDINGS, INC., BANK OF AMERICA, NATIONAL ASSOCIATION) with 8747332 CFPB complaints; 187 email addresses (xxxxxxxxxxxxxxxxxxxxxxxx@vmh5.grup...
Details
Linked Company Activity
Connected Entities
Linked Companies
Related Phone Numbers
Related Domains
Community Reports
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Wells-Fargo-Cards.com Phishing SMS text I received a SMS text on my mobile this evening from something with the number 950-1 that read: "protect@wells-fargo-cards.com / Protection / Customer Protection: www.wells-fargo-cards.com" I ran a whois search on this and found that the site was just registered today. I sent an email to the registrar abuse email link listed in the whois info, and to the official Wells Fargo fraud department. I also called the number of the individual listed in the whois as the admin and tech contact for the site (with my caller ID blocked of course). He did not answer, but his voice mail indicated a name other than the one listed in the site info. I gave him a small piece of my mind, then told him to do his own look-up of the site if he had no idea what I was talking about. I figured there is a fair chance that the registrant info is all fake. Finally, I did a quick scan with NMAP of the IP address and found out that the site doesn't have a firewall, and pretty much all of the ports are open. If anyone wants to have some fun with them, be my guest. I am putting this out for informational purposes, in case someone else has received the SMS msg and is looking for information on it. Please don't visit the site, as I have no idea what is waiting for you there. Here is the whois info (NMAP info tacked on at the end): **WHOIS for wells-fargo-cards.com** Email abuse@melbourneit.com.au is associated with ~1,676,862 domains lima@mail.ru Reverse Whois Registrar MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Registrar Status ok Dates Created on 2016-05-28 - Expires on 2017-05-28 - Updated on 2016-05-28 Name Server(s) NS1.WELLS-FARGO-CARDS.COM NS2.WELLS-FARGO-CARDS.COM IP Address 185.106.22.71 - 9 other sites hosted on this server IP Location Turkey - Amasya - Amasya - Tugba Karacaga Trading As Akon Teknoloji ASN Turkey AS43260 DGN DGN TEKNOL
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.
Proton Pass — Unique passwords for every account
After a breach, reused passwords let attackers into your other accounts. Proton Pass generates and stores a unique password for each one.