nordp[.]tempurl[.]host
“nordp.tempurl.host”
Зведення доказів
Analysis of nordp.tempurl.host shows that the domain is currently offline but retains a set of infrastructure indicators consistent with a brand‑impersonation campaign targeting WordPress users. The domain was registered on August 11 2020 through Amazon Registrar, Inc. and is served by four Amazon Route 53 name servers (ns‑1651.awsdns‑14.co.uk, ns‑736.awsdns‑28.net, ns‑1353.awsdns‑41.org, ns‑117.awsdns). DNS resolution points to the single IPv4 address 70.34.194.77, which belongs to AS20473 The Constant Company, LLC and is geolocated to Sweden. No TLS certificate is presented, indicating that the site would have been served over plain HTTP if it were active. The page title returned by the server is identical to the domain name, providing no additional branding or content cues.
Reputation services flag the domain as malicious. Gridinsoft assigns a trust score of 0 / 100, and the domain is listed on one external blocklist. PhishDestroy has already taken the domain offline, and VirusTotal records show that 13 of 95 scanned security vendors flagged the host, reinforcing the malicious classification. The campaign is explicitly labeled as “Brand Impersonation” and the target brand is identified as WordPress, suggesting that any future content would likely attempt to lure WordPress administrators or end‑users into divulging credentials.
Because the site is not reachable, direct content analysis is not possible, leaving the exact phishing page layout and payload unknown. Nevertheless, the combination of a recent registration, Amazon‑hosted name servers, a low‑trust score, multiple vendor detections, and explicit branding in the intelligence set indicates a high likelihood that the domain was employed for credential‑theft or other unauthorized access attempts against WordPress services. Defenders should continue to block the domain at perimeter filters, monitor DNS queries for the associated IP address, and add the host to internal threat‑intel feeds.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога