# PhishDestroy threat dossier — stage-fps.npr.org ================================================================ Fetched: 2026-07-29 03:48:32 UTC Canonical: https://phishdestroy.io/domain/stage-fps.npr.org/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 45/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 23.36.162.216 (DE, Frankfurt am Main) ASN: AS20940 Akamai International B.V. Hosting org: Akamai Technologies Registrar: MarkMonitor Inc. Nameservers: ["ns-1227.awsdns-25.org", "ns-139.awsdns-17.com", "ns-1580.awsdns-05.co.uk", "ns-769.awsdns-32.net"] HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-17 Status: INVALID chain Fingerprint: 8b32e2b120ed26929893edd24febc9483c41c11dc1a27ad42281cba511f395b6 Subject Alternative Names (related infrastructure — often same operator): - about.npr.org - analytics.npr.org - api-s1.npr.org - api-s4.npr.org - api.npr.org - app.npr.org - arts.npr.org - askmeanother.npr.org - books.npr.org - build.npr.org - bundles-prod.npr.org - bundles-s1.npr.org - bundles-s4.npr.org - bundles.npr.org - cpa.ds.npr.org ... +83 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 09:53:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 04:20:26 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 09:54:35 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is stage-fps.npr.org a Phishing Redirect or Legitimate NPR Test Analysis of stage-fps.npr.org as of July 28, 2026, indicates this domain is currently under investigation for potential phishing activity, though concrete evidence of malicious intent remains limited. The domain is registered through MarkMonitor Inc., a registrar commonly used by legitimate organizations, and resolves to Amazon Web Services nameservers, suggesting enterprise-grade hosting infrastructure. At the time of assessment, the domain returns an HTTP 302 redirect status, which is often used for temporary URL forwarding but can also be leveraged in phishing campaigns to obscure final destinations. One security vendor, PhishDestroy, has blocked the domain, and it appears on a single security blocklist, though the specific criteria for inclusion are not disclosed. VirusTotal scanning by 91 vendors yielded no detections, though this absence does not confirm safety, as phishing domains frequently evade detection during early deployment. The domain remains active, and its association with NPR’s subdomain structure may imply a staging or functional testing environment, though this has not been independently verified. No brand impersonation, phishing kit signatures, or page content details are currently available, limiting definitive classification. Defenders should treat this domain with caution: monitor for unexpected redirects, inspect HTTP headers for anomalous behavior, and cross-reference with internal NPR infrastructure documentation to determine legitimacy. If the domain is not part of authorized NPR operations, blocking or sinkholing may be warranted pending further analysis. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 8b32e2b120ed26929893edd24febc9483c41c11dc1a27ad42281cba511f395b6 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/stage-fps.npr.org/ JSON API: https://api.destroy.tools/v1/check?domain=stage-fps.npr.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 191,831 domains (82,883 alive under monitoring, 107,637 confirmed takedowns/dead). Site: https://phishdestroy.io