Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
07673105002020-11-28103.224.182.207Safari
tierdomaincountregistrarname_serversorg
0tier_1animewapers.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1blacherreport.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_1asdfsadf.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1arphanetbr.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_1boardsgalore.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_1appsclaro.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_1babyshower-decorations.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1apmazon.com1TLD Registrar Solutions Ltd.NS1.ABOVE.COMWhois Privacy Corp.
8tier_1animekiller.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_192dresses.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_2xml.sedodna.com8PSI-USA, Inc. dba Domain RobotNS-1222.AWSDNS-24.ORGNone
11tier_2bidr.trellian.com6ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
12tier_2build.mediapicker.com3GoDaddy.com, LLCRAQUEL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2seemlast.monster3NoneNoneNone
14tier_2ww2.siteplug.com3NoneNoneNone
15tier_2sopho-kat.com2Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
16tier_2amzn.to2NoneNoneNone
17tier_2rd.bizrate.com2MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
18tier_2rd.connexity.net2NoneNoneNone
19tier_2bodybuilding.sjv.io2GANDI SASNS-545.AWSDNS-04.NETNone
20tier_3macpaw.com3GANDI SASNS-1492.AWSDNS-58.ORGMacPaw Family Ltd.
21tier_3irl.com2GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
22tier_3amazon.com2MarkMonitor, Inc.NS1.P31.DYNECT.NETAmazon Technologies, Inc.
23tier_3bodybuilding.com2NoneNoneNone
24tier_3boot-upcompletely-therefinedfile.best1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
25tier_3boot-upintensely-thesophisticatedfile.best1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
26tier_3samsclub.com_LOOP_11NoneNoneNone
27tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETNone
28tier_3boot-upprecise-theintenselyfile.best1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
29tier_3theconnectvpn.com1DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
iphostnamecityregionorgpostalcountry_nametiercount
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_119
191.195.240.136nanMunichBavariaAS47846 SEDO GmbH80331Germanytier_29
2173.239.53.32nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_28
3103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_26
418.210.49.168ec2-18-210-49-168.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23
5192.138.218.207rd.bizrate.comSeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_23
6199.59.242.153nanTampaFloridaAS395082 Bodis, LLC33609United Statestier_23
7216.139.248.127216-139-248-127.aus.us.siteprotect.comAustinTexasAS32400 Hostway Services, Inc.73301United Statestier_23
867.199.248.13cname.bitly.comNew York CityNew YorkAS396982 Google LLC10010United Statestier_22
995.211.26.199nanAmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_22
1054.225.132.253ec2-54-225-132-253.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22
1175.101.207.6ec2-75-101-207-6.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33
1235.224.231.200200.231.224.35.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_33
13100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32
1423.44.211.112a23-44-211-112.deploy.static.akamaitechnologies.comEdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_32
15192.81.212.192nanNorth BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31
1613.225.224.25server-13-225-224-25.jfk51.r.cloudfront.netNew York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_31
17104.248.50.87nanNorth BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31
1823.33.97.165a23-33-97-165.deploy.static.akamaitechnologies.comNew York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31
19104.77.220.218a104-77-220-218.deploy.static.akamaitechnologies.comNew York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31
20104.27.186.165nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website