MALICIOUS — CRITICAL
drivenow[.]site
Analysis of drivenow.site as of 2026-08-04 indicates that the domain is actively flagged for generic phishing.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Disponibilidade
- Último ativo conhecido · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@porkbun.com.
The latest stored availability evidence still shows the domain reachable; 4 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
drivenow.site — Último ativo conhecido (HTTP 200). Resumo das evidências: VirusTotal 3/91 (alphaMountain.ai, Forcepoint ThreatSeeker, SOCRadar); PhishDestroy score 71/100. Registrador: Porkbun.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
Analysis of drivenow.site as of 2026-08-04 indicates that the domain is actively flagged for generic phishing. The only concrete indicator is its presence on a security blocklist, specifically listed by PhishDestroy, which classifies the domain as a phishing source. VirusTotal has processed the domain with 91 scanning engines; none of the engines reported a detection at the time of the scan. The lack of detections does not constitute evidence of cleanliness, especially given the blocklist entry.
The single blocklist entry suggests that the domain has been observed in phishing campaigns, but the limited number of listings may reflect recent emergence or low distribution of observables. No additional infrastructure details such as registrar information, hosting IP, ASN, TLS certificate, or HTTP response codes have been disclosed in the current intelligence feed, leaving much of the operational profile unknown. The generic phishing classification implies attempts to harvest credentials, yet the targeted brand cannot be confirmed from the available data. Defenders should treat the domain as malicious until further analysis proves otherwise.
Recommended actions include adding drivenow.site to web-filter deny lists, blocking network connections to its resolved IPs, and monitoring outbound DNS queries for the domain. If the domain appears in internal logs, analysts should correlate the activity with credential‑phishing attempts and consider user‑education reminders about unsolicited login requests. Continuous re-evaluation is advised; additional scans or threat‑intel updates may reveal new indicators such as malicious payloads, command‑and‑control infrastructure, or compromised certificates.
Cobertura dos dados12 recorded checks
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise da configuração do site
Evidências e relatórios externosIndependent lookups and source reports
PD-20260804-753085 Recipient: abuse@porkbun.com Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.