Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
092891610432021-02-17103.224.182.207Safari
tierdomaincountregistrarname_serversorg
0tier_1boytoyfashion.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1animewapers.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_1alldownloadgames.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1atcmia.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_1alixepress.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_1blacherreport.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_1arphanetbr.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1allpose.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
8tier_1boardsgalore.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_1asignaturecommunity.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_21redira.com12ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
11tier_2xml.sedodna.com8PSI-USA, Inc. dba Domain RobotNS-1222.AWSDNS-24.ORGNone
12tier_2click.expmediadirect.com8NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
13tier_20redirb.com7ABOVE.COM PTY LTD.NS1.ABOVE.COMREDACTED FOR PRIVACY
14tier_2qqnhwxpz.ancientopossum.com6NoneNoneNone
15tier_2seemlast.monster6NoneNoneNone
16tier_2salo57.admedit.net4NoneNoneNone
17tier_2ww2.siteplug.com4DOMAINPEOPLE, INC.NS-1263.AWSDNS-29.ORGREDACTED FOR PRIVACY
18tier_2track.vcdc.com3Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
19tier_2changeslots.com2Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
20tier_3macpaw.com6GANDI SASNS-1492.AWSDNS-58.ORGMacPaw Family Ltd.
21tier_3theconnectvpn.com2DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
22tier_3searchfrequently.com2GoDaddy.com, LLCNEIL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
23tier_3cyberghostvpn.com2GANDI SASNS01.CYBERGHOSTVPN.COMCyberGhost SA
24tier_3iosrecommendedvpn.com2NoneNoneNone
25tier_3bodybuilding.com2MarkMonitor, Inc.NS1.BODYBUILDING.COMVitalize, LLC
26tier_3best.aliexpress.com2Alibaba Cloud Computing (Beijing) Co., Ltd.NS1.ALIBABADNS.COMNone
27tier_3free2update.yourbettercleanplayer.info1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
28tier_3modcloth.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMModCloth Inc
29tier_3upalways.thebettercleanplayers.info1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
iphostnamecityregionorgpostalcountry_nametiercountanycast
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_131nan
1103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_212nan
291.195.240.136nanMunichBavariaAS47846 SEDO GmbH80331Germanytier_28nan
3173.239.53.32nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_28nan
4198.134.116.30nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_28nan
5103.224.212.247lb-212-247.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_27nan
6137.74.180.226ip226.ip-137-74-180.euStrasbourgGrand EstAS16276 OVH SAS67000Francetier_25nan
7104.21.68.220nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_24True
885.17.29.187nanAmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_24nan
9216.139.248.127216-139-248-127.aus.us.siteprotect.comAustinTexasAS32400 Hostway Services, Inc.73301United Statestier_24nan
1023.36.196.16a23-36-196-16.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS16625 Akamai Technologies, Inc.19099United Statestier_32nan
1135.224.231.200200.231.224.35.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_36nan
1254.162.183.76ec2-54-162-183-76.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_35nan
13172.67.181.234nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32True
14104.20.174.46nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32True
15100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32nan
1623.193.181.211a23-193-181-211.deploy.static.akamaitechnologies.comNew York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_32nan
1723.36.196.16a23-36-196-16.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS16625 Akamai Technologies, Inc.19099United Statestier_32nan
18104.21.8.61nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
19104.16.79.42nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
20104.19.182.41nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website