MALICIOUS — HIGH
sorttools[.]xyz
5 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer); the latest stored check returned HTTP 502.
- VirusTotal
- 5 detections
- Blocklists
- 1 · ScamSniffer
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
sorttools.xyz — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 5 detections (engine total unavailable) (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Kayıt kuruluşu: NiceNIC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Digest
sorttools.xyz is classified high with an evidence score of 65/100. 5 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer). Registered 29 Apr 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED, hosted on 188.114.96.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 3 May 2026.
Stored generated summary (templated)mistral · 26.06.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, sorttools.xyz, operates as a credential harvesting portal under the guise of an Online Active Connect service. Analysis indicates the site is designed to deceive users into submitting sensitive authentication details, likely targeting corporate or cloud service credentials. The page title, Online Active Connect, suggests an attempt to impersonate legitimate remote access or identity verification systems, a common tactic in phishing campaigns aimed at enterprise environments. Infrastructure analysis reveals multiple red flags supporting the malicious classification. The domain was registered on April 29, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.96.3 and is currently offline, though prior activity was detected. Security vendors on VirusTotal flagged the domain at a rate of 5 out of 95, indicating moderate but consistent detection across threat intelligence platforms. Additionally, the domain appears on two security blocklists, further confirming its malicious intent. Technologies detected include Framer Sites, React, HSTS, and Cloudflare Browser Insights, which may be leveraged to enhance the site's legitimacy and evade basic detection mechanisms. Users who visited sorttools.xyz should take immediate action to mitigate potential compromise. If credentials were entered, they must be changed across all platforms where reused, with priority given to work-related or financial accounts. System scans using updated security tools are recommended to detect any secondary payloads or persistent threats. Browser data, including cookies and cached credentials, should be cleared to remove any residual artifacts. Organizations should review authentication logs for unusual access patterns and consider implementing multi-factor authentication if not already in place. Given the elevated risk level, monitoring for phishing-related incidents should be heightened for at least 30 days following exposure.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:21:45 UTC
Teknolojiler · 6 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com %100 güvenReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of sorttools.xyz · checked Jun 26, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260503-9EEA25 Recipient: abuse@nicenic.net, abuse@gen.xyz Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.