Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02532589370142021-04-10185.107.56.199Iphone
tierdomaincountregistrarname_serversorg
0tier_1awword.co1Communigal Communication Ltdns2.commonmx.comNone
1tier_1c2sd.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
2tier_1emmaplays.co1Communigal Communication Ltdns2.commonmx.comNone
3tier_1affordableglass.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1conspir4cy.org1Domaincapitan.com LLCNS1.COMMONMX.COMNone
5tier_1beactivedentist.com1SNAPNAMES 7, LLCNS1.COMMONMX.COMNone
6tier_1asio.pro1DYNADOT LLCNS1.COMMONMX.COMNone
7tier_1derechosdeautor.co1GoDaddy.com, LLCns2.commonmx.comNone
8tier_1buengobiernoenred.co1Communigal Communication Ltdns2.commonmx.comNone
9tier_1assuncionistas.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2aristo-hag.com86Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2btpnav.com781API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2atnpx.com64GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2changeslots.com52Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
14tier_2ad.doubleclick.net42MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
15tier_2click.expmediadirect.com38NoneNoneNone
16tier_2api.quotes.com32Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
17tier_2btpnative.com251API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
18tier_2infopicked.com25NoneNoneNone
19tier_2p274639.infopicked.com21NoneNoneNone
20tier_2rd.bizrate.com10MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
21tier_2rd.connexity.net8NoneNoneNone
22tier_2link.sylikes.com7NoneNoneNone
23tier_262758.click.validclick.net6Safenames LtdNS1.FULLMAILBOX.COMNone
24tier_2r.ealeo.com4DYNADOT LLCNS-1186.AWSDNS-20.ORGNone
25tier_2c.clickprotects.com4GoDaddy.com, LLCNS63.DOMAINCONTROL.COMDomains By Proxy, LLC
26tier_211165151.addotnet.com4GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
27tier_2geo.itunes.apple.com4CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
28tier_2itunes.apple.com4CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
29tier_263110.click.validclick.net3Safenames LtdNS1.FULLMAILBOX.COMNone
30tier_3theconnectvpn.com52DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
31tier_3kbb.com42CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
32tier_3bestappland.me36NoneNoneNone
33tier_3robogarden.io22GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
34tier_3storystudio.sfgate.com8CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
35tier_3storystudio.chron.com6CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Newspapers, LLC
36tier_3fanatics.com4MarkMonitor, Inc.A1-147.AKAM.NETFanatics Inc.
37tier_3music.apple.com4CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
38tier_3storystudio.mysanantonio.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMThe Hearst Corporation
39tier_3wayfair.com3NoneNoneNone
40tier_3aristo-hag.com2Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
41tier_3crutchfield.com1Domain.com, LLCNS1.CRUTCHFIELD.COMREDACTED FOR PRIVACY
42tier_363084.click.validclick.net1Safenames LtdNS1.FULLMAILBOX.COMNone
43tier_3michaelkors.com1NOM-IQ Ltd dba Com LaudeA1-111.AKAM.NETMichael Kors, L.L.C.
44tier_3joinsmarty.com1NoneNoneNone
45tier_3filter.onwardclick.com1NoneNoneNone
46tier_3birkenstock.com1PSI-USA, Inc. dba Domain RobotA.NS14.NETBIRKENSTOCK SALES GMBH
47tier_3bestbody.s3.amazonaws.com1MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
48tier_363110.click.validclick.net1Safenames LtdNS1.FULLMAILBOX.COMNone
49tier_3childrensplace.com1CSC CORPORATE DOMAINS, INC.PDNS1.CSCDNS.NETThe Childrens Place Services Company, LLC
ipcityregionorgpostalcountry_nametiercountanycasthostname
0207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
2207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_117nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_18nannan
8185.107.56.198RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
9185.107.56.199RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2104nannan
11172.67.74.77San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_255Truenan
1234.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_252nanec2-34-207-32-33.compute-1.amazonaws.com
13173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_246nan18.65.c0ad.ip4.static.sl-reverse.com
14198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_238nannan
155.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_232nannan
1652.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_220nanec2-52-72-29-7.compute-1.amazonaws.com
1752.206.108.38AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_218nanec2-52-206-108-38.compute-1.amazonaws.com
18192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_217nannan
19204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_32nan204.44.79.214.static.quadranet.com
2054.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31nanec2-54-208-107-202.compute-1.amazonaws.com
21172.217.3.102WestburyNew YorkAS15169 Google LLC11590United Statestier_216nanlga34s18-in-f6.1e100.net
2218.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213nanec2-18-235-67-128.compute-1.amazonaws.com
2334.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31nanec2-34-197-176-2.compute-1.amazonaws.com
24172.217.165.134Los AngelesCaliforniaAS15169 Google LLC90009United Statestier_211nanlax30s03-in-f6.1e100.net
25209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_210nannan
26172.217.11.6New York CityNew YorkAS15169 Google LLC10004United Statestier_29nanlga25s60-in-f6.1e100.net
27192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_28nanrd.connexity.net
2834.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26nanec2-34-207-43-7.compute-1.amazonaws.com
29173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
30172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_343Truenan
3123.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_339nana23-44-217-143.deploy.static.akamaitechnologies.com
32142.93.4.215North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_336nannan
3398.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_317nannan
34104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311Truenan
35172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311Truenan
36104.21.91.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_39Truenan
37100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_34nanpool-100-37-135-2.nycmny.fios.verizon.net
38184.87.65.240NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33nana184-87-65-240.deploy.static.akamaitechnologies.com
3923.1.205.179EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_33nana23-1-205-179.deploy.static.akamaitechnologies.com
4023.39.32.237NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33nana23-39-32-237.deploy.static.akamaitechnologies.com
41204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_32nan204.44.79.214.static.quadranet.com
42205.196.12.74WashingtonWashington, D.C.AS54391 Crutchfield New Media LLC20045United Statestier_31nanwww.crutchfield.com
43184.85.16.53NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31nana184-85-16-53.deploy.static.akamaitechnologies.com
44104.26.13.42San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31Truenan
4523.0.199.211EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31nana23-0-199-211.deploy.static.akamaitechnologies.com
46173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
4734.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31nanec2-34-197-176-2.compute-1.amazonaws.com
4854.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31nanec2-54-208-107-202.compute-1.amazonaws.com
4923.59.250.35NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31nana23-59-250-35.deploy.static.akamaitechnologies.com
5052.216.88.11AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nans3-1-w.amazonaws.com
51184.85.4.64NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31nana184-85-4-64.deploy.static.akamaitechnologies.com

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website