Analysis indicates that wbellbill.netlify.app is an active phishing domain targeting Wells Fargo customers, as of July 28, 2026. The domain is hosted on Netlify's platform and resolves to IP address 63.176.8.218, though no nameservers are currently associated with it. Security vendors have flagged this domain, with 14 out of 91 detection engines on VirusTotal identifying it as malicious. Additionally, the domain appears on two security blocklists, including PhishDestroy and OpenPhish, further corroborating its classification as a phishing threat.
Infrastructure analysis reveals that the domain remains operational, with no indications of takedown or deactivation. The lack of nameserver records (NS_NOT_FOUND) may suggest an attempt to obscure ownership or hosting details, though this is not uncommon for domains registered through cloud-based hosting services like Netlify. The IP address 63.176.8.218 does not provide additional context regarding the hosting provider or geographic location at this time. Defenders should prioritize blocking access to wbellbill.netlify.app at the network and endpoint levels, given its presence on multiple blocklists and detection by security vendors.
Organizations should also monitor for any attempts to exploit this domain in phishing campaigns, particularly those impersonating Wells Fargo branding or communications. While the exact content of the phishing page has not been analyzed, the domain's classification as a high-risk threat warrants immediate mitigation. No further details regarding the phishing kit, SSL certificate, or HTTP response codes are available at this time.