nordp[.]tempurl[.]host
“nordp.tempurl.host”
Zusammenfassung der Beweislage
Analysis of nordp.tempurl.host shows that the domain is currently offline but retains a set of infrastructure indicators consistent with a brand‑impersonation campaign targeting WordPress users. The domain was registered on August 11 2020 through Amazon Registrar, Inc. and is served by four Amazon Route 53 name servers (ns‑1651.awsdns‑14.co.uk, ns‑736.awsdns‑28.net, ns‑1353.awsdns‑41.org, ns‑117.awsdns). DNS resolution points to the single IPv4 address 70.34.194.77, which belongs to AS20473 The Constant Company, LLC and is geolocated to Sweden. No TLS certificate is presented, indicating that the site would have been served over plain HTTP if it were active. The page title returned by the server is identical to the domain name, providing no additional branding or content cues.
Reputation services flag the domain as malicious. Gridinsoft assigns a trust score of 0 / 100, and the domain is listed on one external blocklist. PhishDestroy has already taken the domain offline, and VirusTotal records show that 13 of 95 scanned security vendors flagged the host, reinforcing the malicious classification. The campaign is explicitly labeled as “Brand Impersonation” and the target brand is identified as WordPress, suggesting that any future content would likely attempt to lure WordPress administrators or end‑users into divulging credentials.
Because the site is not reachable, direct content analysis is not possible, leaving the exact phishing page layout and payload unknown. Nevertheless, the combination of a recent registration, Amazon‑hosted name servers, a low‑trust score, multiple vendor detections, and explicit branding in the intelligence set indicates a high likelihood that the domain was employed for credential‑theft or other unauthorized access attempts against WordPress services. Defenders should continue to block the domain at perimeter filters, monitor DNS queries for the associated IP address, and add the host to internal threat‑intel feeds.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt