Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
027428910120152021-04-15185.107.56.199Android
tierdomaincountregistrarname_serversorg
0tier_1bitenergy.org1Allearthdomains.com LLCNS1.COMMONMX.COMStatutory Masking Enabled
1tier_1mymp3songs.co1GoDaddy.com, LLCns2.commonmx.comNone
2tier_1checkvin.us1Communigal Communication Ltdns1.commonmx.comNone
3tier_1esox.me1Dynadot, LLCNoneNone
4tier_1aeinrst.info1DYNADOT LLCNS1.COMMONMX.COMNone
5tier_1inaharquitectos.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1animeai2.net1Slow Putt Domains LLCNS1.COMMONMX.COMNone
7tier_1hireachbb.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159507725
8tier_1bbt79.com1Communigal Communication LtdNS1.COMMONMX.COMNone
9tier_1androidupdate.pro1DYNADOT LLCNS1.COMMONMX.COMNone
10tier_21496.rawlexi.com159GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
11tier_2americanlisted.com148ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
12tier_2click.appcast.io70101Domain GRS LtdNS-85.AWSDNS-10.COMNone
13tier_2aristo-hag.com29Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
14tier_29nl.es21NoneNoneNone
15tier_2newre-conversions.clickmeter.com21REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
16tier_2btpnav.com191API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
17tier_2ring.joveo.com18Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
18tier_2media-px.com15GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
19tier_2joblift.com11INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMREDACTED FOR PRIVACY
20tier_2click.appcast.io_LOOP_110NoneNoneNone
21tier_2p.nexxt.com9Network Solutions, LLCNS21.WORLDNIC.COMNone
22tier_2api.l5srv.net8GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
23tier_2track.vcdc.com8Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
24tier_263084.click.validclick.net5Safenames LtdNS1.FULLMAILBOX.COMNone
25tier_2click.expmediadirect.com4NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
26tier_2api.apptap.com4Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
27tier_2api.mplayit.com4Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
28tier_2redirect.viglink.com4Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
29tier_2link.sylikes.com4MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
30tier_3google.com75MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
31tier_3careerbuilder.com17CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
32tier_3signup.finddreamjobs.com13GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
33tier_3robogarden.io13GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
34tier_3storystudio.sfgate.com12CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
35tier_3americanlisted.com10ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
36tier_3upward.careers8GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
37tier_3signup.careersandjobs.co5GoDaddy.com, LLCalexis.ns.cloudflare.comDomains By Proxy, LLC
38tier_3nextcareernow.com4GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
39tier_3jobleads.com4united domains AGCRUZ.NS.CLOUDFLARE.COMNone
40tier_3click.appcast.io3101Domain GRS LtdNS-85.AWSDNS-10.COMNone
41tier_3linkedin.com3MarkMonitor, Inc.DNS1.P09.NSONE.NETLinkedIn Corporation
42tier_3joblift.com_LOOP_13NoneNoneNone
43tier_3click.appcast.io_LOOP_12NoneNoneNone
44tier_3socalhondadealers.com2DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
45tier_3blair.com2CSC CORPORATE DOMAINS, INC.NS-1237.AWSDNS-26.ORGBluestem Brands, Inc.
46tier_3trk.careerbliss.com1GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
47tier_3thredup.com_LOOP_11NoneNoneNone
48tier_3appliancesconnection.com1GoDaddy.com, LLCNS67.DOMAINCONTROL.COMDomains By Proxy, LLC
49tier_3joblift.com1INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMREDACTED FOR PRIVACY
50tier_3api.l5srv.net1GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
51tier_3rd.bizrate.com1MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
52tier_3linkup.com1GoDaddy.com, LLCNS-102.AWSDNS-12.COMJobDig
53tier_3caregivers.careinhomes.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMRedacted for Privacy Purposes
54tier_3intelliapp.driverapponline.com1ENOM, INC.ITZEL.NS.CLOUDFLARE.COMWhois Privacy Protection Service, Inc.
55tier_3m.gladplacespin.xyz1Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
56tier_3google.com_LOOP_11NoneNoneNone
57tier_3cmp.jobs1NoneNS1.LINODE.COMNone
58tier_3jobg8.com1REGISTER S.P.A.RES1.AMGSHAREDSERVICES.COMJobg8 Limited
59tier_3win5.trustedpush.com1NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_134nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
3207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_116nannan
5104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
6206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
837.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
974.63.241.22DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1422-241-63-74.static.reverse.lstn.netnan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_2159nannan
1135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_310240.61.209.35.bc.googleusercontent.comnan
1252.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_225ec2-52-3-4-129.compute-1.amazonaws.comnan
13100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-100-25-52-1.compute-1.amazonaws.comnan
14209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_222nannan
153.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-3-234-0-165.compute-1.amazonaws.comnan
1623.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-23-21-166-45.compute-1.amazonaws.comnan
1754.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-54-235-205-204.compute-1.amazonaws.comnan
18204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_212204.44.79.214.static.quadranet.comnan
1935.190.64.22Kansas CityMissouriAS15169 Google LLC64121United Statestier_3122.64.190.35.bc.googleusercontent.comTrue
20100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_311pool-100-37-135-2.nycmny.fios.verizon.netnan
2168.168.84.60NorristownPennsylvaniaAS17378 TierPoint, LLC19403United Statestier_21160.84.168.68.static.dbsintl.netnan
2234.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-34-197-176-2.compute-1.amazonaws.comnan
2323.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-23-21-53-13.compute-1.amazonaws.comnan
2454.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-54-197-247-190.compute-1.amazonaws.comnan
2567.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_31nannan
26192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_28rd.bizrate.comnan
27172.67.134.220San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_28nanTrue
28167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_28static.197.8.233.167.clients.your-server.denan
2954.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-54-208-107-202.compute-1.amazonaws.comnan
30172.217.10.100CliftonNew JerseyAS15169 Google LLC07015United Statestier_323lga34s15-in-f4.1e100.netnan
31172.217.12.132CliftonNew JerseyAS15169 Google LLC07015United Statestier_313lga34s19-in-f4.1e100.netnan
32142.250.64.68WestburyNew YorkAS15169 Google LLC11590United Statestier_313lga34s30-in-f4.1e100.netnan
33172.217.165.132New York CityNew YorkAS15169 Google LLC10004United Statestier_313lax30s03-in-f4.1e100.netnan
34100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_311pool-100-37-135-2.nycmny.fios.verizon.netnan
35151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_311nanTrue
3635.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_310240.61.209.35.bc.googleusercontent.comnan
37104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_39nanTrue
3867.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_38nannan
39172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
40172.217.12.196CliftonNew JerseyAS15169 Google LLC07015United Statestier_37lga25s63-in-f4.1e100.netnan
4199.84.114.74NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_37server-99-84-114-74.ewr52.r.cloudfront.netnan
4299.84.114.78NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_36server-99-84-114-78.ewr52.r.cloudfront.netnan
43172.217.7.4Clinton CornersNew YorkAS15169 Google LLC12514United Statestier_36lga25s56-in-f4.1e100.netnan
44104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
45104.21.10.65San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
46104.17.48.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
47216.239.32.21Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_34any-in-2015.1e100.netTrue
48194.6.195.224HamburgHamburgAS39227 Corpex Internet GmbH20038Germanytier_34www.jobleads.denan
4999.84.114.84NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-114-84.ewr52.r.cloudfront.netnan
5035.174.35.73AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-35-174-35-73.compute-1.amazonaws.comnan
5123.73.247.49EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_32a23-73-247-49.deploy.static.akamaitechnologies.comnan
5213.107.42.14RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32nanTrue
5399.84.114.91NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-114-91.ewr52.r.cloudfront.netnan
543.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-3-234-0-165.compute-1.amazonaws.comnan
55207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_31cbsmtp1.careerbliss.comnan
56100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-100-25-52-1.compute-1.amazonaws.comnan
5724.157.42.211New York CityNew YorkAS6128 Cablevision Systems Corp.10004United Statestier_31189d2ad3.cst.lightpath.netnan
5835.190.64.22Kansas CityMissouriAS15169 Google LLC64121United Statestier_3122.64.190.35.bc.googleusercontent.comTrue
5967.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_31nannan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website