Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
05135201792202020-10-26103.224.182.207Iphone
tierdomaincountregistrarname_serversorg
0tier_1puracandelatv.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1taglicapellicorti.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_1codanova.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1channelfilipino.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_1dudroid.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_1secondnaturecd.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_103calls.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1pornolan.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
8tier_1soal-psikotest.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_1ohne-kohlenhydrate.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_2bidr.trellian.com380ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
11tier_2changeslots.com265Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
12tier_2go.trackinz.com56NAMECHEAP INCNS-1139.AWSDNS-14.ORGWhoisGuard, Inc.
13tier_2us.redirectbuzz.club43Gandi SASns-2.awsdns-00.comPPCBUZZ
14tier_20redira.com32ABOVE.COM PTY LTD.NS1.ABOVE.COMREDACTED FOR PRIVACY
15tier_2technoblogs.net20GANDI SASNS-1196.AWSDNS-21.ORGPPCBUZZ
16tier_2paid.outbrain.com14Network Solutions, LLCDNS1.P07.NSONE.NETNone
17tier_2amobil.online13Gandi SASNS-1714.AWSDNS-22.CO.UKNone
18tier_2gofast.pw12NoneNoneNone
19tier_211164440.searchiqnet.com11GoDaddy.com, LLCNS57.DOMAINCONTROL.COMDomains By Proxy, LLC
20tier_3theconnectvpn.com265DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
21tier_3clickherefun.com53NoneNoneNone
22tier_3clk.news-headlines.co16NoneNoneNone
23tier_3bet.com13MarkMonitor, Inc.DNS1.P09.NSONE.NETBlack Entertainment Television LLC
24tier_3securelygains.com12GRANSY S.R.O D/B/A SUBREG.CZNS1.NIBH-OFFERS.COMWhois protection, this company does not own this domain name s.r.o.
25tier_3samsung.com8NoneNoneNone
26tier_3amobil.online7Gandi SASNS-1714.AWSDNS-22.CO.UKNone
27tier_3pes20.proasdf.com5GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
28tier_3amazon.com5MarkMonitor, Inc.NS1.P31.DYNECT.NETAmazon Technologies, Inc.
29tier_3google.com_LOOP_13NoneNoneNone
iphostnamecityregionorgpostalcountry_nametiercount
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_1414
1100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_316
2103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_2380
334.207.32.33ec2-34-207-32-33.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_2265
434.226.252.28ec2-34-226-252-28.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_256
5103.224.212.241lb-212-241.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_232
6209.132.243.15nanWyomingMichiganAS7296 Alchemy Communications, Inc.49509United Statestier_225
7151.101.2.132nanSydneyNew South WalesAS54113 Fastly1001Australiatier_214
869.162.65.2424-65-162-69.static.reverse.lstn.netDallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_212
966.232.112.8266-232-112-82.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_29
1066.232.112.8766-232-112-87.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_27
1166.232.112.9166-232-112-91.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_27
12104.27.187.165nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_392
13172.67.181.234nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_391
14104.27.186.165nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_382
15144.202.92.101144.202.92.101.vultr.comWashingtonVirginiaAS20473 Choopa, LLC22747United Statestier_353
16100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_316
1723.47.147.121a23-47-147-121.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS16625 Akamai Technologies, Inc.19099United Statestier_313
1823.38.172.65a23-38-172-65.deploy.static.akamaitechnologies.comNewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_37
1952.203.50.59ec2-52-203-50-59.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_36
2052.45.50.0ec2-52-45-50-0.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_35
21162.243.10.151nanNew York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_35

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website