Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02422438231182021-04-07185.107.56.199Safari
tierdomaincountregistrarname_serversorg
0tier_1ehacker.co1Dynadot LLCns2.commonmx.comNone
1tier_1foto-ramki.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
2tier_1focoonline.info1Dynadot, LLCNS1.COMMONMX.COMNone
3tier_1azulholisticspa.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
4tier_1coupeclub.cc1Zinc Domain Names LLCNS1.COMMONMX.COMNone
5tier_1bexinhs.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1hao678.info1Dynadot, LLCNS1.COMMONMX.COMNone
7tier_1apknyot.info1Dynadot, LLCNS1.COMMONMX.COMNone
8tier_1camkiss.info1SiteName Ltd.NS1.COMMONMX.COMNone
9tier_1dinosriverwest.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
10tier_2click.expmediadirect.com120NoneNoneNone
11tier_2rqhere2.com111NoneNoneNone
12tier_2btpnav.com551API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
13tier_21496.rawlexi.com42GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
14tier_2americanlisted.com41ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_2nizephoros-pom.com12Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
16tier_2rugab-ans.com8Amazon Registrar, Inc.NS-1165.AWSDNS-17.ORGWhois Privacy Service
17tier_2atnpx.com5GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
18tier_2asufij.xyz5NoneNoneNone
19tier_2managerformula.com4NoneNoneNone
20tier_2rtbstream.com41API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
21tier_2ad.doubleclick.net3MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
22tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
23tier_2api.mplayit.com2Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
24tier_2redirect.viglink.com2Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
25tier_2link.sylikes.com2NoneNoneNone
26tier_2hureseyd.top2NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
27tier_2blockchain-com.email2NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
28tier_2storage-for-mobileapps.life2NoneNoneNone
29tier_2filter.explorads.com2GoDaddy.com, LLCNS1.LINODE.COMDomains By Proxy, LLC
30tier_3thehealthlevel.info56NoneNoneNone
31tier_3us.tideri.com41united domains AGNS.UDAG.DENone
32tier_3youthandcare.info40NoneNoneNone
33tier_3nutrahealth.info9GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
34tier_3managerformula.com7NoneNoneNone
35tier_3fithealthspark.info6GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
36tier_3xzb.subeamy.pw5NoneNoneNone
37tier_3s3.amazonaws.com5MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
38tier_3kbb.com4CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
39tier_3rd.bizrate.com2NoneNoneNone
40tier_3storystudio.sfgate.com2CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
41tier_3play.google.com2NoneNoneNone
42tier_3go-x34n7wbcoes-ok.live2NoneNoneNone
43tier_3americanlisted.com1ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
44tier_3wayfair.com1NoneNoneNone
45tier_3robogarden.io1GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
46tier_3apple.global-info.space1NoneNoneNone
47tier_3goldstar.com1ENOM, INC.NS-102.AWSDNS-12.COMREDACTED FOR PRIVACY
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_125nannan
3207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_116nannan
5206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_111nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
882.192.82.227AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
937.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2122nannan
11167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_2111nannan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_260nannan
13198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_243nannan
1435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_31240.61.209.35.bc.googleusercontent.comnan
1518.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-18-235-67-128.compute-1.amazonaws.comnan
16104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_24nanTrue
1754.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-54-208-107-202.compute-1.amazonaws.comnan
1834.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-34-197-176-2.compute-1.amazonaws.comnan
19192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_32rd.bizrate.comnan
2052.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-52-72-29-7.compute-1.amazonaws.comnan
2134.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-34-207-43-7.compute-1.amazonaws.comnan
2252.33.20.119BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_23ec2-52-33-20-119.us-west-2.compute.amazonaws.comnan
2344.239.66.208BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_22ec2-44-239-66-208.us-west-2.compute.amazonaws.comnan
2452.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-52-205-177-114.compute-1.amazonaws.comnan
25204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_22204.44.79.214.static.quadranet.comnan
26185.233.2.13Saint PetersburgSt.-PetersburgAS48096 Enterprise Cloud Ltd.190000Russiatier_22nannan
275.8.47.52HaarlemNorth HollandAS209813 Fast Content Delivery LTD2031Netherlandstier_22nannan
2845.77.159.202New York CityNew YorkAS20473 The Constant Company, LLC10004United Statestier_2245.77.159.202.vultr.comnan
2923.73.247.181EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_22a23-73-247-181.deploy.static.akamaitechnologies.comnan
3035.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_341123.171.246.35.bc.googleusercontent.comnan
31172.67.220.94San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_333nanTrue
32104.21.11.199San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_325nanTrue
33104.21.75.98San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_323nanTrue
34172.67.167.55San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_315nanTrue
35172.67.141.3San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
36172.67.200.87San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
3723.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_34a23-44-217-143.deploy.static.akamaitechnologies.comnan
38104.21.70.248San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
3952.88.215.122BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_33ec2-52-88-215-122.us-west-2.compute.amazonaws.comnan
4035.165.21.241BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_32ec2-35-165-21-241.us-west-2.compute.amazonaws.comnan
41192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_32rd.bizrate.comnan
42172.232.19.138NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_32a172-232-19-138.deploy.static.akamaitechnologies.comnan
4398.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_32nannan
4452.217.193.64AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
45172.217.9.238CliftonNew JerseyAS15169 Google LLC07015United Statestier_32lga34s11-in-f14.1e100.netnan
46104.21.86.43San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4735.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_31240.61.209.35.bc.googleusercontent.comnan
4823.200.0.40EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_31a23-200-0-40.deploy.static.akamaitechnologies.comnan
4923.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-99.deploy.static.akamaitechnologies.comnan
50104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5152.216.98.125AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
52172.67.223.4San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5323.200.0.11EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_31a23-200-0-11.deploy.static.akamaitechnologies.comnan
5450.18.212.168San JoseCaliforniaAS16509 Amazon.com, Inc.95103United Statestier_31ec2-50-18-212-168.us-west-1.compute.amazonaws.comnan
5523.200.0.32EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_31a23-200-0-32.deploy.static.akamaitechnologies.comnan
56104.21.21.208San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5752.216.178.141AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5823.200.0.21EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_31a23-200-0-21.deploy.static.akamaitechnologies.comnan
59172.232.19.147NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a172-232-19-147.deploy.static.akamaitechnologies.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website