Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02602668900182021-04-11185.107.56.199Safari
tierdomaincountregistrarname_serversorg
0tier_1androidzoo.in1Dynadot LLCns1.commonmx.comNone
1tier_1edupromocodes.com1NoneNoneNone
2tier_1786.name1NoneNoneNone
3tier_1examnotes.net1NameSilo, LLCNS1.COMMONMX.COMSee PrivacyGuardian.org
4tier_1alinaplugaru.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
5tier_1articlecms.in1Dynadot LLCns1.commonmx.comNone
6tier_1kurdforums.co1GoDaddy.com, LLCns1.commonmx.comNone
7tier_1dominiosinnova.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
8tier_1imagefiles.me1GoDaddy.com, LLCNoneNone
9tier_1garsworld.com1Shining Star Domains, LLCNS1.COMMONMX.COMNone
10tier_2click.expmediadirect.com112NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
11tier_2rqhere2.com106NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
12tier_2btpnav.com551API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
13tier_21496.rawlexi.com38NoneNoneNone
14tier_2americanlisted.com37ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_29nl.es18NoneNoneNone
16tier_2newre-conversions.clickmeter.com18REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
17tier_2nizephoros-pom.com17Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
18tier_2managerformula.com13NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
19tier_2click.appcast.io13101Domain GRS LtdNS-85.AWSDNS-10.COMNone
20tier_2trk.jometer.com13Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
21tier_2api.l5srv.net12GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
22tier_2aristo-hag.com10Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
23tier_2ring.joveo.com5Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
24tier_2asufij.xyz4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
25tier_2atnpx.com3GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
26tier_2hureseyd.top3NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
27tier_2whatjobs.com3123-Reg LimitedVIDA.NS.CLOUDFLARE.COMNone
28tier_2us.tideri.com2united domains AGNS.UDAG.DENone
29tier_2clk.rtpdn12.com2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
30tier_3wellnessfolk.club62NAMECHEAP INCmolly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
31tier_3healthysight.club43NAMECHEAP INCmolly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
32tier_3s3.amazonaws.com14MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
33tier_3upward.careers12GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
34tier_3us.tideri.com8united domains AGNS.UDAG.DENone
35tier_3click.appcast.io5101Domain GRS LtdNS-85.AWSDNS-10.COMNone
36tier_3xzb.subeamy.pw4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
37tier_3managerformula.com3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
38tier_3signup.finddreamjobs.com3GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
39tier_3click.appcast.io_LOOP_13NoneNoneNone
40tier_3kbb.com2CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
41tier_3blockchain-com.email2NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
42tier_3signup.careersandjobs.co2GoDaddy.com, LLCalexis.ns.cloudflare.comDomains By Proxy, LLC
43tier_3wayfair.com2MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
44tier_3filter.onwardclick.com1NameCheap, Inc.NS1.ENCONTEXT.COMNone
45tier_3trk.careerbliss.com1GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
46tier_3rd.bizrate.com1NoneNoneNone
47tier_3beyourxfriend.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
48tier_3google.com_LOOP_11NoneNoneNone
49tier_3google.com1NoneNoneNone
50tier_3robogarden.io1GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
51tier_3bing.com_LOOP_11NoneNoneNone
52tier_3play.google.com1NoneNoneNone
53tier_3careerbuilder.com1CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
54tier_3music.apple.com1CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
55tier_3jobleads.com1united domains AGCRUZ.NS.CLOUDFLARE.COMNone
56tier_3godaddy.com1GoDaddy.com, LLCA1-245.AKAM.NETGo Daddy Operating Company, LLC
57tier_3bestsecretflirt.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
58tier_3venturefizz.com1GoDaddy.com, LLCELLIOT.NS.CLOUDFLARE.COMNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
3207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_119nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_117nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
882.192.82.227AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
9185.107.56.199RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2113nannan
11167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_2106nannan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_255nannan
13198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_238nannan
1435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_237240.61.209.35.bc.googleusercontent.comnan
1567.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_212nannan
1623.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-23-21-53-13.compute-1.amazonaws.comnan
1723.21.166.230AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-23-21-166-230.compute-1.amazonaws.comnan
1854.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-54-197-247-190.compute-1.amazonaws.comnan
1934.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-34-197-176-2.compute-1.amazonaws.comnan
2054.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-54-235-205-204.compute-1.amazonaws.comnan
213.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-3-234-0-165.compute-1.amazonaws.comnan
2218.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-18-235-67-128.compute-1.amazonaws.comnan
2352.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-52-72-29-7.compute-1.amazonaws.comnan
2454.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-54-208-107-202.compute-1.amazonaws.comnan
2523.43.56.185New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_24a23-43-56-185.deploy.static.akamaitechnologies.comnan
2652.33.20.119BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_24ec2-52-33-20-119.us-west-2.compute.amazonaws.comnan
2799.84.114.53NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_24server-99-84-114-53.ewr52.r.cloudfront.netnan
2899.84.114.65NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_24server-99-84-114-65.ewr52.r.cloudfront.netnan
29100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-100-25-52-1.compute-1.amazonaws.comnan
30172.67.176.98San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_337nanTrue
31104.21.72.73San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_325nanTrue
32104.21.64.39San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_325nanTrue
33172.67.175.235San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_318nanTrue
3467.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_312nannan
3535.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_38123.171.246.35.bc.googleusercontent.comnan
36100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_38pool-100-37-135-2.nycmny.fios.verizon.netnan
3735.165.21.241BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_34ec2-35-165-21-241.us-west-2.compute.amazonaws.comnan
3852.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-52-3-4-129.compute-1.amazonaws.comnan
3952.216.251.70AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
40100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-100-25-52-1.compute-1.amazonaws.comnan
41104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
42104.21.10.65San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4352.216.93.221AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4423.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-41-189-99.deploy.static.akamaitechnologies.comnan
4552.217.32.246AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
4652.217.48.246AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
47173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
48207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_31cbsmtp1.careerbliss.comnan
4923.43.56.194New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_31a23-43-56-194.deploy.static.akamaitechnologies.comnan
5023.1.205.179EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-1-205-179.deploy.static.akamaitechnologies.comnan
5152.217.65.22AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5223.43.56.203New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_31a23-43-56-203.deploy.static.akamaitechnologies.comnan
53192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31nannan
5445.33.8.244RichardsonTexasAS63949 Linode, LLC75080United Statestier_31li962-244.members.linode.comnan
5552.216.100.5AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
56172.217.6.196WestburyNew YorkAS15169 Google LLC11590United Statestier_31lga25s54-in-f4.1e100.netnan
5752.217.93.246AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5823.43.56.211New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_31a23-43-56-211.deploy.static.akamaitechnologies.comnan
5952.216.66.35AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website