ontario[.]safedrivinggovbr[.]cc
ontario.safedrivinggovbr.cc — Непроверенный. Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 10/91 (BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet, G-Data); PhishDestroy score 80/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, ontario.safedrivinggovbr.cc, is identified as a phishing site designed to mimic official Canadian government transportation portals. Analysis indicates the infrastructure is engineered for credential harvesting, specifically targeting driver license and vehicle registration details. The domain employs social engineering tactics, presenting itself as a legitimate Ontario driving service portal to deceive users into submitting sensitive personal information. No direct association with known drainer kits or cryptocurrency scams has been established, but the focus on government credentials elevates the risk profile for identity theft and fraud. Infrastructure analysis reveals the domain was registered on June 12, 2026, through Gname.com Pte. Ltd., a registrar frequently observed in phishing campaigns. It resolves to the IP address 43.166.232.20, which has been flagged in prior malicious activity reports. As of the latest assessment, the domain appears on one security blocklist and is detected by 7 out of 95 security vendors on VirusTotal, indicating moderate but consistent detection across threat intelligence platforms. The domain is not currently listed on Google Safe Browsing, suggesting either a recent deployment or evasion of broader detection mechanisms. The domain has since been taken offline, likely in response to security vendor interventions or registrar enforcement actions. However, the infrastructure remains a residual risk, as the IP address and registrar history may be reused for future phishing operations. Users who interacted with the domain prior to its takedown should assume credential exposure and initiate identity verification protocols. Organizations are advised to monitor for similar domains leveraging government-themed lures and update blocklists to include the IP address 43.166.232.20 as a precautionary measure.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание