Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
027729012070162021-04-07185.107.56.199Chrome
tierdomaincountregistrarname_serversorg
0tier_1ehacker.co1Dynadot LLCns2.commonmx.comNone
1tier_1foto-ramki.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
2tier_1bexinhs.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1hao678.info1Dynadot, LLCNS1.COMMONMX.COMNone
4tier_1apknyot.info1Dynadot, LLCNS1.COMMONMX.COMNone
5tier_1institutoraulporras.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1camkiss.info1SiteName Ltd.NS1.COMMONMX.COMNone
7tier_1dinosriverwest.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
8tier_1besturl.info1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1hotroz.info1Dynadot, LLCNS1.COMMONMX.COMNone
10tier_2btpnav.com771API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2click.expmediadirect.com62NoneNoneNone
12tier_21496.rawlexi.com48GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
13tier_2americanlisted.com46ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
14tier_2traff0121.com34NoneNoneNone
15tier_2mediagate.club34NoneNoneNone
16tier_20.mediagate.club34NoneNoneNone
17tier_2rugab-ans.com33Amazon Registrar, Inc.NS-1165.AWSDNS-17.ORGWhois Privacy Service
18tier_21.mediagate.club33NoneNoneNone
19tier_22.mediagate.club28NoneNoneNone
20tier_3aliexpress.com_LOOP_122NoneNoneNone
21tier_3bing.com20MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
22tier_3us.tideri.com19united domains AGNS.UDAG.DENone
23tier_3nutrahealth.info9GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
24tier_3fithealthspark.info7GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
25tier_33.mediagate.club6NoneNoneNone
26tier_32.mediagate.club5NoneNoneNone
27tier_3cehappear.fun5Dynadot LLCAIDEN.NS.CLOUDFLARE.COMNone
28tier_3kbb.com4CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
29tier_3dl0lhqr3fd1yh.cloudfront.net3NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_118nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
774.63.241.25DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1625-241-63-74.static.reverse.lstn.netnan
8104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
974.63.241.30DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1430-241-63-74.static.reverse.lstn.netnan
10178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_312nannan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_293nannan
12198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_262nannan
1388.99.101.106Hohen NeuendorfBrandenburgAS24940 Hetzner Online GmbH16540Germanytier_256static.106.101.99.88.clients.your-server.denan
14198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_248nannan
1535.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_32240.61.209.35.bc.googleusercontent.comnan
16209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_223static-42-202-205-209.24shells.netnan
17209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_223static-43-202-205-209.24shells.netnan
1835.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_223ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
1923.36.196.16PhiladelphiaPennsylvaniaAS16625 Akamai Technologies, Inc.19099United Statestier_222a23-36-196-16.deploy.static.akamaitechnologies.comnan
20167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_216nannan
21207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_32cbsmtp1.careerbliss.comnan
22100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_332pool-100-37-135-2.nycmny.fios.verizon.netnan
23173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21418.65.c0ad.ip4.static.sl-reverse.comnan
24192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33rd.bizrate.comnan
2518.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213ec2-18-235-67-128.compute-1.amazonaws.comnan
2654.210.170.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213ec2-54-210-170-165.compute-1.amazonaws.comnan
2752.29.135.45Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_212ec2-52-29-135-45.eu-central-1.compute.amazonaws.comnan
283.125.109.211Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_211ec2-3-125-109-211.eu-central-1.compute.amazonaws.comnan
2950.16.173.246AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-50-16-173-246.compute-1.amazonaws.comnan
30100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_332pool-100-37-135-2.nycmny.fios.verizon.netnan
3135.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_319123.171.246.35.bc.googleusercontent.comnan
32178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_312nannan
33204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_38a-0001.a-msedge.netTrue
34104.21.21.208San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
35172.67.141.3San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
3613.107.22.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_36nanTrue
37131.253.33.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_35a-0001.dc-msedge.netTrue
3823.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_34a23-44-217-143.deploy.static.akamaitechnologies.comnan
39104.21.70.248San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
40192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33rd.bizrate.comnan
41199.83.128.213Redwood CityCaliforniaAS19551 Incapsula Inc94065United Statestier_33199.83.128.213.ip.incapdns.netTrue
4234.192.40.54AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-34-192-40-54.compute-1.amazonaws.comnan
4335.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_32240.61.209.35.bc.googleusercontent.comnan
4499.84.41.100NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-41-100.ewr52.r.cloudfront.netnan
4523.43.253.154NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-43-253-154.deploy.static.akamaitechnologies.comnan
46104.21.83.108San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
47207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_32cbsmtp1.careerbliss.comnan
4899.83.180.214SeattleWashingtonAS16509 Amazon.com, Inc.98108United Statestier_32a6733df31c115e5a2.awsglobalaccelerator.comTrue
4952.85.132.55AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32server-52-85-132-55.iad50.r.cloudfront.netnan
50104.22.55.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
5134.196.177.100AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-34-196-177-100.compute-1.amazonaws.comnan
52143.204.147.112NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-143-204-147-112.ewr52.r.cloudfront.netnan
5399.84.114.112NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-112.ewr52.r.cloudfront.netnan
54173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
5534.251.34.108DublinLeinsterAS16509 Amazon.com, Inc.D02Irelandtier_31ec2-34-251-34-108.eu-west-1.compute.amazonaws.comnan
5654.234.245.31AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-234-245-31.compute-1.amazonaws.comnan
5799.84.41.171NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-41-171.ewr52.r.cloudfront.netnan
58104.18.23.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5999.84.176.109WashingtonWashington, D.C.AS16509 Amazon.com, Inc.20045United Statestier_31server-99-84-176-109.iad89.r.cloudfront.netnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website