MALICIOUS — CRITICAL
soorgroup[.]ca
This domain, soorgroup.ca, is specifically flagged as a fake login phishing site.
- VirusTotal
- 19/91
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
soorgroup.ca — Контент недоступний (HTTP 502). Уособлення бренду: Xfinity; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; URLScan malicious verdict; PhishStats feed match; PhishDestroy score 100/100. Реєстратор: Go Daddy Domains Canada.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This domain, soorgroup.ca, is specifically flagged as a fake login phishing site. The domain is designed to mimic legitimate login pages, often targeting users by impersonating well-known services or brands to steal credentials and personal information. Once visited, users are prompted to enter sensitive data, which is then captured by the attackers.
Analysis indicates that soorgroup.ca has been flagged by 20 out of 95 security vendors on VirusTotal, suggesting a significant level of suspicion among cybersecurity professionals. The domain was registered through Go Daddy Domains Canada, Inc on June 15, 2022. It resolves to the IP address 68.66.226.89 and has been taken offline. The site has a Gridinsoft trust score of 0/100 and a Scamadviser trust score of 1/100, both indicating a high risk of malicious activity. Additionally, the domain appears on one security blocklist and is blocked by PhishDestroy. The site uses technologies such as WordPress, MySQL, PHP, and LiteSpeed, and has implemented HSTS and HTTP/3, which can make it appear more legitimate to unsuspecting users.
If users have visited soorgroup.ca, they should immediately change their passwords for any accounts they may have entered credentials into on the site. It is also recommended to monitor their accounts for any unauthorized activity and to run a full system scan using updated antivirus software. Users should report the incident to their IT department or cybersecurity team and avoid clicking on any links or providing further information to the domain.
Обсяг даних13 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | soorgroup.ca/r/xifix/xinfini/ |
malware | Detects file containing Telegram Bot API |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 6 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance web server compatible with Apache configurations.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of soorgroup.ca · checked Jun 26, 2026
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.