Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
04534732703202020-11-09103.224.182.207Android
tierdomaincountregistrarname_serversorg
0tier_1bellsoutj.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1codanova.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_1channelfilipino.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1soal-psikotest.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_1ddiziizle.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_1benstreaming.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_1ecatomb.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1a-doctor-in-the-house.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
8tier_1ptidico.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_1azmovielist.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_2bidr.trellian.com240ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
11tier_2us.redirectbuzz.club173Gandi SASns-2.awsdns-00.comPPCBUZZ
12tier_2recode.pw170Gandi SASNS-1611.AWSDNS-09.CO.UKNone
13tier_2portablemusic.mobi167GoDaddy.com, LLCNoneNone
14tier_2thespook.xyz139Name.com, Inc.MARK.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
15tier_2trk81.onnur.xyz138NameSilo, LLCPAITYN.NS.CLOUDFLARE.COMSee PrivacyGuardian.org
16tier_2cmon.ueive.com117NAMECHEAP INCCOBY.NS.CLOUDFLARE.COMWhoisGuard, Inc.
17tier_2go.doblevialatam.com103GoDaddy.com, LLCNS.RACKSPACE.COMDomains By Proxy, LLC
18tier_2sales.dvlatam.xyz95NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
19tier_2cheaposflight.com57NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
20tier_3google.com_LOOP_155NoneNoneNone
21tier_3for-ap.com40PDR Ltd. d/b/a PublicDomainRegistry.comALEX.NS.CLOUDFLARE.COMNone
22tier_3trustedpush.com23NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
23tier_3win1.trustedpush.com14NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
24tier_3win3.trustedpush.com11NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
25tier_3sales.dvlatam.xyz8NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
26tier_3samsung.com8NoneNoneNone
27tier_3win2.trustedpush.com8NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
28tier_3winningpokernetwork.com7Safenames LtdNASH.NS.CLOUDFLARE.COMNone
29tier_3playgames-win.com7Arsys Internet, S.L. dba NICLINE.COMNS23.PIENSASOLUTIONS.COMluis martinez agullo
iphostnamecityregionorgpostalcountry_nametiercount
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_1288
1100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_398
2103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_2240
3162.242.198.222nanWashingtonWashington, D.C.AS27357 Rackspace Hosting20045United Statestier_2103
4184.154.10.251server04.com-2.mobiChicagoIllinoisAS32475 SingleHop LLC60666United Statestier_38
534.199.180.187ec2-34-199-180-187.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_290
6172.64.197.11nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_289
7172.64.162.32nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_262
8165.22.162.145nanSanta ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_255
9172.64.163.32nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_255
10104.27.133.11nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_254
11172.64.196.11nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_249
12100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_398
13104.18.45.36nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_316
14172.67.139.49nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313
1513.225.65.110server-13-225-65-110.ewr53.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_313
16104.18.44.36nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311
17184.154.10.251server04.com-2.mobiChicagoIllinoisAS32475 SingleHop LLC60666United Statestier_38
1813.225.65.6server-13-225-65-6.ewr53.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_37
1923.38.172.65a23-38-172-65.deploy.static.akamaitechnologies.comNewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_37
2013.225.65.102server-13-225-65-102.ewr53.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_37
2166.228.63.84nb-66-228-63-84.atlanta.nodebalancer.linode.comAtlantaGeorgiaAS63949 Linode, LLC30302United Statestier_37

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website