Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
03813871373102020-10-28103.224.182.207Iphone
tierdomaincountregistrarname_serversorg
0tier_1puracandelatv.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1codanova.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_1dudroid.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1secondnaturecd.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_1vvvgrace.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_103calls.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_1soal-psikotest.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1ddiziizle.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
8tier_1benstreaming.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_1a-doctor-in-the-house.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_2bidr.trellian.com276ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
11tier_2changeslots.com216Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
12tier_2go.trackinz.com46NoneNoneNone
13tier_20redira.com33ABOVE.COM PTY LTD.NS1.ABOVE.COMREDACTED FOR PRIVACY
14tier_2us.redirectbuzz.club14Gandi SASns-2.awsdns-00.comPPCBUZZ
15tier_2recode.pw14Gandi SASNS-1611.AWSDNS-09.CO.UKNone
16tier_2api.apientry.com10GoDaddy.com, LLCELMA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
17tier_2portablemusic.mobi10GoDaddy.com, LLCNoneNone
18tier_211164440.searchiqnet.com8GoDaddy.com, LLCNS57.DOMAINCONTROL.COMDomains By Proxy, LLC
19tier_2susd.lugos-cla.com7Amazon Registrar, Inc.NS-1412.AWSDNS-48.ORGWhois Privacy Service
20tier_3theconnectvpn.com216DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
21tier_3checkherefun.com39NoneNoneNone
22tier_3pes20.proasdf.com10GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
23tier_3promotionsonlineus.com7GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMNone
24tier_3localpages.com4Network Solutions, LLCNS1.FABULOUSCDN.COMNone
25tier_3carsnspeed.net4GANDI SASNS-1120.AWSDNS-12.ORGPPCBUZZ
26tier_3amazon.com3MarkMonitor, Inc.NS1.P31.DYNECT.NETAmazon Technologies, Inc.
27tier_3samsung.com3NoneNoneNone
28tier_3play.google.com3MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
29tier_3minecraft.net3TUCOWS, INC.NS-1395.AWSDNS-46.ORGContact Privacy Inc. Customer 0120735043
iphostnamecityregionorgpostalcountry_nametiercount
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_1310
1103.224.212.221lb-212-221.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_11
2103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_2276
334.207.32.33ec2-34-207-32-33.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_2216
434.226.252.28ec2-34-226-252-28.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_246
5103.224.212.241lb-212-241.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_233
6209.132.243.15nanWyomingMichiganAS7296 Alchemy Communications, Inc.49509United Statestier_221
734.199.107.160ec2-34-199-107-160.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_214
867.212.173.78server04.com-2.mobiChicagoIllinoisAS32475 SingleHop LLC60666United Statestier_27
954.175.126.175ec2-54-175-126-175.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_26
10172.64.132.8nanGreenvilleSouth CarolinaAS13335 Cloudflare, Inc.29616United Statestier_26
1131.170.100.125nanMadridMadridAS201942 Soltia Consulting SL28001Spaintier_26
12172.67.181.234nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_399
13104.27.186.165nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_374
14104.27.187.165nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_343
15157.245.227.32nanSanta ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_339
16162.243.10.151nanNew York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_310
1766.63.171.20066.63.171.200.static.quadranet.comLos AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_34
18172.64.100.4nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_34
1913.225.224.25server-13-225-224-25.jfk51.r.cloudfront.netAtlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_33
2023.221.210.196a23-221-210-196.deploy.static.akamaitechnologies.comNewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33
21172.64.101.4nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_33

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website