Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
03693881815002020-11-08103.224.182.207Android
tierdomaincountregistrarname_serversorg
0tier_1puracandelatv.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1codanova.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_1secondnaturecd.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1vvvgrace.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_103calls.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_1ddiziizle.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_1benstreaming.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1a-doctor-in-the-house.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
8tier_1ptidico.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_1posteos.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_2bidr.trellian.com178ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
11tier_2us.redirectbuzz.club116Gandi SASns-2.awsdns-00.comPPCBUZZ
12tier_2recode.pw116Gandi SASNS-1611.AWSDNS-09.CO.UKNone
13tier_2portablemusic.mobi112GoDaddy.com, LLCNoneNone
14tier_2trk77.onnur.xyz87NameSilo, LLCPAITYN.NS.CLOUDFLARE.COMSee PrivacyGuardian.org
15tier_2thespook.xyz60Name.com, Inc.MARK.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
16tier_2google.com57MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
17tier_2trkads.info55DANESCO TRADING LTDNS1.DIGITALOCEAN.COMDANESCO TRADING LTD.
18tier_2cmon.ueive.com52NoneNoneNone
19tier_2go.doblevialatam.com38GoDaddy.com, LLCNS.RACKSPACE.COMDomains By Proxy, LLC
20tier_3google.com_LOOP_157NoneNoneNone
21tier_3for-ap.com14PDR Ltd. d/b/a PublicDomainRegistry.comALEX.NS.CLOUDFLARE.COMPrivacy Protect, LLC (PrivacyProtect.org)
22tier_3encryptalert.com11NoneNoneNone
23tier_3winningpokernetwork.com9Safenames LtdNASH.NS.CLOUDFLARE.COMNone
24tier_3coercially.club9NoneNoneNone
25tier_3wayfair.com6MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
26tier_3panel-surveys.com6NoneNoneNone
27tier_3sales.dvlatam.xyz4NoneNoneNone
28tier_3portablemusic.mobi4GoDaddy.com, LLCNoneNone
29tier_3nutaku.net4Eurodns S.A.DNS1.P03.NSONE.NETWhois Privacy (enumDNS dba)
iphostnamecityregionorgpostalcountry_nametiercount
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_1213
1103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_2178
2165.22.162.145nanSanta ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_255
3172.64.197.11nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_248
4172.64.196.11nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_239
5162.242.198.222nanWashingtonWashington, D.C.AS27357 Rackspace Hosting20045United Statestier_238
634.199.180.187ec2-34-199-180-187.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_238
7184.154.10.251server04.com-2.mobiChicagoIllinoisAS32475 SingleHop LLC60666United Statestier_34
8172.64.103.28nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_231
9213.32.106.141ip141.ip-213-32-106.euAmsterdamNorth HollandAS16276 OVH SAS1012Netherlandstier_230
1037.187.75.92ns3365200.ip-37-187-75.euSaumontNouvelle-AquitaineAS16276 OVH SAS47600Francetier_229
11100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_379
12144.202.107.3144.202.107.3.vultr.comLive OakCaliforniaAS20473 Choopa, LLC95953United Statestier_313
13172.67.139.49nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_38
14104.16.246.78nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36
15217.163.30.151217.163.30.151.vultr.comFuyongGuangdongAS20473 Choopa, LLCnanChinatier_36
16104.18.45.36nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35
17184.154.10.251server04.com-2.mobiChicagoIllinoisAS32475 SingleHop LLC60666United Statestier_34
1866.254.114.112reflectededge.reflected.netHopewellNew JerseyAS29789 Reflected Networks, Inc.08525United Statestier_34
19167.114.209.62ais-sa2-bhs04-1.cdnstream.comMississaugaOntarioAS16276 OVH SASL5BCanadatier_33
2045.33.9.36li963-36.members.linode.comRichardsonTexasAS63949 Linode, LLC75080United Statestier_33

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website