Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
025126911300172021-04-09185.107.56.199Safari
tierdomaincountregistrarname_serversorg
0tier_1karsiyakadenizsurucukursu.org1NoneNoneNone
1tier_1yongkangstreet.org1NoneNoneNone
2tier_1androidzoo.in1Dynadot LLCns1.commonmx.comNone
3tier_1cuuveed.com1DYNADOT17 LLCNS1.COMMONMX.COMNone
4tier_1tamiat.org1NoneNoneNone
5tier_1cclover.me1NoneNoneNone
6tier_1affordableglass.org1NoneNoneNone
7tier_1conspir4cy.org1NoneNoneNone
8tier_1chagford-accom.co.uk1Virtua Drug Ltd t/a autoBackorder [Tag = AUTOBACKORDER]nNone
9tier_1elinformativohipico.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2btpnav.com761API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2click.expmediadirect.com63NoneNoneNone
12tier_2api.apptap.com45Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
13tier_2redirect.viglink.com44Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
14tier_2link.sylikes.com44MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
15tier_21496.rawlexi.com42GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
16tier_2americanlisted.com41ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
17tier_2rd.bizrate.com40MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
18tier_2wayfair.com32NoneNoneNone
19tier_2rd.connexity.net31NoneNoneNone
20tier_2api.mplayit.com29Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
21tier_2aristo-hag.com27Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
22tier_2nizephoros-pom.com25Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
23tier_29nl.es23NoneNoneNone
24tier_2newre-conversions.clickmeter.com23REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
25tier_2trk.jometer.com19Amazon Registrar, Inc.NS-129.AWSDNS-16.COMNone
26tier_2managerformula.com15NoneNoneNone
27tier_2api.l5srv.net15GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
28tier_2asufij.xyz13NoneNoneNone
29tier_2click.appcast.io12NoneNoneNone
30tier_3wayfair.com_LOOP_132NoneNoneNone
31tier_3s3.amazonaws.com16MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
32tier_3upward.careers15GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
33tier_3xzb.subeamy.pw13NoneNoneNone
34tier_3us.tideri.com12united domains AGNS.UDAG.DENone
35tier_3managerformula.com9NoneNoneNone
36tier_3rd.bizrate.com8MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
37tier_3blockchain-com.email7NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
38tier_3bing.com6NoneNoneNone
39tier_3kbb.com5CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
40tier_3runnewest-bestextremelyfile.best4NoneNoneNone
41tier_3play.google.com3MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
42tier_3google.com3NoneNoneNone
43tier_3signup.finddreamjobs.com3GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
44tier_3wayfair.com3NoneNoneNone
45tier_3click.appcast.io_LOOP_13NoneNoneNone
46tier_3skechers.com2NoneNoneNone
47tier_3linkedin.com2NoneNoneNone
48tier_3birkenstock.com2PSI-USA, Inc. dba Domain RobotA.NS14.NETBIRKENSTOCK SALES GMBH
49tier_3surfisnow.com1GoDaddy.com, LLCDNS1.P09.NSONE.NETClientConnect LTD
50tier_3rpa21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
51tier_3click.appcast.io1NoneNoneNone
52tier_3thredup.com1GoDaddy.com, LLCMATT.NS.CLOUDFLARE.COMThredUp Inc.
53tier_3aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
54tier_3surveystarz.com1GoDaddy.com, LLCNS13.DOMAINCONTROL.COMDomains By Proxy, LLC
55tier_3whatjobs.com1123-Reg LimitedVIDA.NS.CLOUDFLARE.COMNone
56tier_3signup.careersandjobs.co1GoDaddy.com, LLCalexis.ns.cloudflare.comDomains By Proxy, LLC
57tier_3google.com_LOOP_11NoneNoneNone
58tier_3customerservicejobs.com1ENOM, INC.DNS1.NAME-SERVICES.COMREDACTED FOR PRIVACY
59tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
3207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_117nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_115nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
6206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_111nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
882.192.82.225AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
982.192.82.226AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_287nannan
11192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_38nannan
12198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_263nannan
13198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nannan
1435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_241240.61.209.35.bc.googleusercontent.comnan
1523.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a23-41-189-99.deploy.static.akamaitechnologies.comnan
16192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_231rd.connexity.netnan
1752.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_226ec2-52-206-141-190.compute-1.amazonaws.comnan
1834.197.67.232AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_226ec2-34-197-67-232.compute-1.amazonaws.comnan
193.226.37.31AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_225ec2-3-226-37-31.compute-1.amazonaws.comnan
2052.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-52-205-177-114.compute-1.amazonaws.comnan
2134.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_219ec2-34-225-128-119.compute-1.amazonaws.comnan
2234.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_216ec2-34-207-43-7.compute-1.amazonaws.comnan
2367.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_215nannan
2423.21.166.230AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_214ec2-23-21-166-230.compute-1.amazonaws.comnan
2523.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213ec2-23-21-53-13.compute-1.amazonaws.comnan
2652.206.108.38AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-52-206-108-38.compute-1.amazonaws.comnan
27185.233.2.13Saint PetersburgSt.-PetersburgAS48096 Enterprise Cloud Ltd.190000Russiatier_211nannan
28173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_210nannan
2954.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-54-235-205-204.compute-1.amazonaws.comnan
30100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_339pool-100-37-135-2.nycmny.fios.verizon.netnan
3167.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_315nannan
3252.88.215.122BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_312ec2-52-88-215-122.us-west-2.compute.amazonaws.comnan
3335.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_312123.171.246.35.bc.googleusercontent.comnan
34192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_38nannan
35204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_35a-0001.a-msedge.netTrue
3623.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_35a23-44-217-143.deploy.static.akamaitechnologies.comnan
375.8.47.52HaarlemNorth HollandAS209813 Fast Content Delivery LTD2031Netherlandstier_34nannan
3852.20.53.118AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34ec2-52-20-53-118.compute-1.amazonaws.comnan
3923.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a23-41-189-99.deploy.static.akamaitechnologies.comnan
4023.200.0.37EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_33a23-200-0-37.deploy.static.akamaitechnologies.comnan
4123.200.0.41EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_33a23-200-0-41.deploy.static.akamaitechnologies.comnan
4252.216.243.182AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
43172.217.165.142Los AngelesCaliforniaAS15169 Google LLC90009United Statestier_32lax30s03-in-f14.1e100.netnan
4452.217.80.182AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
45104.16.188.137San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4613.107.42.14RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32nanTrue
47172.217.10.68CliftonNew JerseyAS15169 Google LLC07015United Statestier_32lga34s14-in-f4.1e100.netnan
4852.217.81.78AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
49104.17.48.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
50162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
5123.200.0.21EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_32a23-200-0-21.deploy.static.akamaitechnologies.comnan
5252.217.99.78AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5323.38.170.120NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_32a23-38-170-120.deploy.static.akamaitechnologies.comnan
5413.33.46.45NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-13-33-46-45.ewr52.r.cloudfront.netnan
5513.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31nanTrue
5652.217.90.30AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
57100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-100-25-52-1.compute-1.amazonaws.comnan
5852.217.92.22AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5952.217.64.46AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website