ontario[.]safedrivinggovbr[.]cc
ontario.safedrivinggovbr.cc — No verificado. Tipo de estafa: Generic Phishing. Resumen de las pruebas: VirusTotal 10/91 (BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet, G-Data); PhishDestroy score 80/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, ontario.safedrivinggovbr.cc, is identified as a phishing site designed to mimic official Canadian government transportation portals. Analysis indicates the infrastructure is engineered for credential harvesting, specifically targeting driver license and vehicle registration details. The domain employs social engineering tactics, presenting itself as a legitimate Ontario driving service portal to deceive users into submitting sensitive personal information. No direct association with known drainer kits or cryptocurrency scams has been established, but the focus on government credentials elevates the risk profile for identity theft and fraud. Infrastructure analysis reveals the domain was registered on June 12, 2026, through Gname.com Pte. Ltd., a registrar frequently observed in phishing campaigns. It resolves to the IP address 43.166.232.20, which has been flagged in prior malicious activity reports. As of the latest assessment, the domain appears on one security blocklist and is detected by 7 out of 95 security vendors on VirusTotal, indicating moderate but consistent detection across threat intelligence platforms. The domain is not currently listed on Google Safe Browsing, suggesting either a recent deployment or evasion of broader detection mechanisms. The domain has since been taken offline, likely in response to security vendor interventions or registrar enforcement actions. However, the infrastructure remains a residual risk, as the IP address and registrar history may be reused for future phishing operations. Users who interacted with the domain prior to its takedown should assume credential exposure and initiate identity verification protocols. Organizations are advised to monitor for similar domains leveraging government-themed lures and update blocklists to include the IP address 43.166.232.20 as a precautionary measure.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.