Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
04494681733102020-10-29103.224.182.207Android
tierdomaincountregistrarname_serversorg
0tier_1erokuni.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1codanova.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_1cocers.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1annagoesshopping.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_1barboach.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_1bellewe.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_103calls.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1dx-torrent.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
8tier_1animewapers.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_1benstreaming.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_2bidr.trellian.com177ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
11tier_2us.redirectbuzz.club171Gandi SASns-2.awsdns-00.comPPCBUZZ
12tier_2recode.pw145Gandi SASNS-1611.AWSDNS-09.CO.UKNone
13tier_2portablemusic.mobi77GoDaddy.com, LLCNoneNone
14tier_2maromorb.com70NameSilo, LLCELMA.NS.CLOUDFLARE.COMSee PrivacyGuardian.org
15tier_20redira.com62ABOVE.COM PTY LTD.NS1.ABOVE.COMREDACTED FOR PRIVACY
16tier_2reroplittrewheck.pro35DANESCO TRADING LTDNS-280.AWSDNS-35.COMDANESCO TRADING LTD.
17tier_2track.fungiers.com35GoDaddy.com, LLCNS73.DOMAINCONTROL.COMNone
18tier_2wolve.pro33DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
19tier_2bxt1.shaperal.com32GoDaddy.com, LLCDESI.NS.CLOUDFLARE.COMNone
20tier_3carsnspeed.net67GANDI SASNS-1120.AWSDNS-12.ORGPPCBUZZ
21tier_3172.104.184.4332Name.com, Inc.NS1.LINODE.COMLinode, LLC
22tier_3pes20.proasdf.com13GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
23tier_3amazon.com11MarkMonitor, Inc.NS1.P31.DYNECT.NETAmazon Technologies, Inc.
24tier_3samsung.com11NoneNoneNone
25tier_3clk.news-headlines.co11NAMECHEAP INCns-1428.awsdns-50.orgWhoisGuard, Inc.
26tier_3blog.sfgate.com6CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
27tier_3macys.com3Network Solutions, LLCA1-135.AKAM.NETNone
28tier_3bizrate.com3MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
29tier_3query.pureleads.com3New Frontier, Inc.NS1.P05.DYNECT.NETDomain Protection Services, Inc.
iphostnamecityregionorgpostalcountry_nametiercount
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_1255
1103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_2177
2103.224.212.241lb-212-241.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_262
3209.132.243.15nanWyomingMichiganAS7296 Alchemy Communications, Inc.49509United Statestier_249
4172.64.108.15nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_237
567.212.173.78server04.com-2.mobiChicagoIllinoisAS32475 SingleHop LLC60666United Statestier_232
6172.64.109.15nanNew York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_230
766.232.112.6866-232-112-68.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_228
866.232.112.7466-232-112-74.static.hvvc.usDenverColoradoAS29802 HIVELOCITY, Inc.80210United Statestier_225
9213.32.106.141ip141.ip-213-32-106.euLuxembourgLuxembourgAS16276 OVH SASL-1118Luxembourgtier_224
1031.170.100.126nanMadridMadridAS201942 Soltia Consulting SL28001Spaintier_220
11100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_337
12172.104.184.43li1775-43.members.linode.comSingaporeSingaporeAS63949 Linode, LLC048508Singaporetier_332
13162.243.10.151nanNew York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_313
1423.221.210.196a23-221-210-196.deploy.static.akamaitechnologies.comNewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_39
1513.225.224.25server-13-225-224-25.jfk51.r.cloudfront.netAtlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_38
1666.232.112.8666-232-112-86.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_37
17151.101.0.200nanSingaporeSingaporeAS54113 Fastly048508Singaporetier_36
1866.232.112.9066-232-112-90.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_36
1966.232.112.8166-232-112-81.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_36
2066.232.112.7366-232-112-73.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_36

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website