Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
025326210011162021-04-16185.107.56.199Android
tierdomaincountregistrarname_serversorg
0tier_1erotop.info1DYNADOT LLCNS1.COMMONMX.COMNone
1tier_1best-ga.me1Dynadot, LLCNoneNone
2tier_1aurbataao.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159179997
3tier_1atransmissionclinic.com1! #1 Host Canada, Inc.NS1.COMMONMX.COMNone
4tier_1skymaps.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
5tier_1bicoholics.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158852663
6tier_1massagista.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1brainwaves.me1Dynadot, LLCNoneNone
8tier_1verid.org1Communigal Communication LtdNS1.COMMONMX.COMNone
9tier_1myvgp.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2aristo-hag.com144Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2btpnav.com1281API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2atnpx.com105GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2ad.doubleclick.net25MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
14tier_2click.expmediadirect.com15NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
15tier_2api.apptap.com13Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
16tier_2api.mplayit.com13Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
17tier_2redirect.viglink.com13Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
18tier_2link.sylikes.com13MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
19tier_2rd.bizrate.com13NoneNoneNone
20tier_2rd.connexity.net12NoneNoneNone
21tier_2rtbstream.com111API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
22tier_2nizephoros-pom.com10Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGNone
23tier_2get.popplunder.com10NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
24tier_2trustedpush.com9NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
25tier_2win1.trustedpush.com9NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
26tier_2media-px.com8GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
27tier_2wayfair.com8MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
28tier_2trackyourmpg.com7GoDaddy Online Services Cayman Islands LTDHUGH.NS.CLOUDFLARE.COMNone
29tier_2btpnative.com71API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
30tier_3kbb.com80CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
31tier_3robogarden.io27GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
32tier_3storystudio.sfgate.com18CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
33tier_3wayfair.com_LOOP_17NoneNoneNone
34tier_3rd.bizrate.com4MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
35tier_3socalhondadealers.com4DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
36tier_3m.gladplacespin.xyz4Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
37tier_3aristo-hag.com3Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGNone
38tier_3win4.trustedpush.com3NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
39tier_3win2.trustedpush.com3NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
40tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
41tier_3ads.midwayusa.com2GoDaddy.com, LLCNS-1486.AWSDNS-57.ORGMidwayUSA
42tier_3moneyfinancegold.com2NAMECHEAP INCANNA.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
43tier_3win5.trustedpush.com2NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
44tier_3ad.doubleclick.net2MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
45tier_3appliancesconnection.com1GoDaddy.com, LLCNS67.DOMAINCONTROL.COMDomains By Proxy, LLC
46tier_3b.playspind.xyz1Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
47tier_3edureka.co1Network Solutions, LLCns-1218.awsdns-24.orgkapil
48tier_3wayfair.com_LOOP_21NoneNoneNone
49tier_3dollartree.com1Network Solutions, LLCA1-230.AKAM.NETNone
50tier_3m.fastmapc.xyz1Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
51tier_3orthofeet.com_LOOP_11NoneNoneNone
52tier_3trustedpush.com1NameCheap, Inc.NS-1142.AWSDNS-14.ORGNone
53tier_3google.com1MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
54tier_3win3.trustedpush.com1NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
55tier_3beyourxfriend.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
56tier_3atnpx.com1GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
57tier_3m.placesiteb.xyz1Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
58tier_3wayfair.com1MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
2104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_123nannan
3207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
4207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_117nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
882.192.82.225AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
974.63.241.21DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1421-241-63-74.static.reverse.lstn.netnan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2147nannan
11172.67.74.77San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_249nanTrue
1234.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-34-197-176-2.compute-1.amazonaws.comnan
13104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
1452.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_240ec2-52-72-29-7.compute-1.amazonaws.comnan
1554.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_237ec2-54-208-107-202.compute-1.amazonaws.comnan
1618.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-18-235-67-128.compute-1.amazonaws.comnan
17192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_34rd.bizrate.comnan
18204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_218204.44.79.214.static.quadranet.comnan
19198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_215nannan
20104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_213nanTrue
213.224.109.140AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-3-224-109-140.compute-1.amazonaws.comnan
22192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_212rd.connexity.netnan
2313.225.62.7NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-13-225-62-7.ewr53.r.cloudfront.netnan
2413.225.62.54NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-13-225-62-54.ewr53.r.cloudfront.netnan
2534.199.180.187AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-34-199-180-187.compute-1.amazonaws.comnan
2613.225.62.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-13-225-62-107.ewr53.r.cloudfront.netnan
2754.197.172.17AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-54-197-172-17.compute-1.amazonaws.comnan
2823.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-99.deploy.static.akamaitechnologies.comnan
2952.21.176.105AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-52-21-176-105.compute-1.amazonaws.comnan
3023.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_380a23-44-217-143.deploy.static.akamaitechnologies.comnan
31172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_319nanTrue
32151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_317nanTrue
33100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_313pool-100-37-135-2.nycmny.fios.verizon.netnan
34104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_38nanTrue
35192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_34rd.bizrate.comnan
3635.174.35.73AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-35-174-35-73.compute-1.amazonaws.comnan
3734.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-34-197-176-2.compute-1.amazonaws.comnan
38162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
39184.85.9.119NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a184-85-9-119.deploy.static.akamaitechnologies.comnan
40104.21.95.173San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
41104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
42104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4313.225.62.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-13-225-62-107.ewr53.r.cloudfront.netnan
4413.225.62.7NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-13-225-62-7.ewr53.r.cloudfront.netnan
4513.225.62.54NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-13-225-62-54.ewr53.r.cloudfront.netnan
46104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4734.207.4.240AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-34-207-4-240.compute-1.amazonaws.comnan
4824.157.42.211New York CityNew YorkAS6128 Cablevision Systems Corp.10004United Statestier_31189d2ad3.cst.lightpath.netnan
49104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5054.192.100.33NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-54-192-100-33.ewr53.r.cloudfront.netnan
5123.73.233.19EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-73-233-19.deploy.static.akamaitechnologies.comnan
52151.101.64.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_31nanTrue
53172.217.10.102CliftonNew JerseyAS15169 Google LLC07015United Statestier_31lga34s15-in-f6.1e100.netnan
54172.217.165.132Los AngelesCaliforniaAS15169 Google LLC90009United Statestier_31lax30s03-in-f4.1e100.netnan
5545.33.8.244RichardsonTexasAS63949 Linode, LLC75080United Statestier_31li962-244.members.linode.comnan
5618.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-18-235-67-128.compute-1.amazonaws.comnan
57104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
58172.217.6.198WestburyNew YorkAS15169 Google LLC11590United Statestier_31lga25s54-in-f198.1e100.netnan
5923.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-99.deploy.static.akamaitechnologies.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website