Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
027227413681152021-04-16185.107.56.199Chrome
tierdomaincountregistrarname_serversorg
0tier_1erotop.info1DYNADOT LLCNS1.COMMONMX.COMNone
1tier_1best-ga.me1Dynadot, LLCNoneNone
2tier_1aurbataao.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159179997
3tier_1atransmissionclinic.com1! #1 Host Canada, Inc.NS1.COMMONMX.COMNone
4tier_1skymaps.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
5tier_1apstc.org1Columbianames.com LLCNS1.COMMONMX.COMStatutory Masking Enabled
6tier_1bankersadda.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1bicoholics.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158852663
8tier_1massagista.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1alinaplugaru.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2btpnav.com1171API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aristo-hag.com84Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_2trak.today-trip.com50NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
13tier_2wirtgage-proxing.icu49Key-Systems GmbHNS-1046.AWSDNS-02.ORGc/o whoisproxy.com
14tier_2secureconv-ec.com49Key-Systems GmbHNS-1437.AWSDNS-51.ORGc/o whoisproxy.com
15tier_2patpat.sjv.io46GANDI SASNS-545.AWSDNS-04.NETNone
16tier_2ojrq.net46GANDI SASNS-1151.AWSDNS-15.ORGImpact Radius
17tier_2patpat.sjv.io_LOOP_146NoneNoneNone
18tier_2patpat.com46ENOM, INC.GINA.NS.CLOUDFLARE.COMWhois Privacy Protection Service, Inc.
19tier_21496.rawlexi.com41GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
20tier_2americanlisted.com40ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
21tier_2click.expmediadirect.com31NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
22tier_2api.apptap.com24Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
23tier_2api.mplayit.com22Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
24tier_2redirect.viglink.com22Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
25tier_2link.sylikes.com22MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
26tier_29nl.es21NoneNoneNone
27tier_2newre-conversions.clickmeter.com21REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
28tier_2trk.jometer.com21Amazon Registrar, Inc.NS-129.AWSDNS-16.COMNone
29tier_2api.l5srv.net21GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
30tier_3us.patpat.com46ENOM, INC.GINA.NS.CLOUDFLARE.COMWhois Privacy Protection Service, Inc.
31tier_3irl.com29GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
32tier_3upward.careers21GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
33tier_3us.tideri.com19united domains AGNS.UDAG.DENone
34tier_3rd.bizrate.com8MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
35tier_3aliexpress.com_LOOP_15NoneNoneNone
36tier_3bostonproper.com4Amazon Registrar, Inc.NS-117.AWSDNS-14.COMNone
37tier_3google.com_LOOP_14NoneNoneNone
38tier_3reebok.com3CSC CORPORATE DOMAINS, INC.NS1.NETNAMES.NETReebok International, Ltd.
39tier_3macys.com3Network Solutions, LLCA1-135.AKAM.NETMacy's Systems and Technology, Inc.
40tier_3ram21.proasdf.com3GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
41tier_3omahasteaks.com3CSC CORPORATE DOMAINS, INC.A1-3.AKAM.NETOmaha Steaks International, Inc.
42tier_3loyality-program.com2Amazon Registrar, Inc.NS-108.AWSDNS-13.COMNone
43tier_3search.discoverweb.com2GoDaddy.com, LLCNINA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
44tier_3www5.securybrowseapp.com2NAMECHEAP INCALEXIS.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
45tier_3fanatics.com2MarkMonitor, Inc.A1-147.AKAM.NETFanatics Inc.
46tier_3wix.com2GoDaddy.com, LLCDNS1.P03.NSONE.NETWix.com, LTD.
47tier_31496.rawlexi.com1GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
48tier_3omahasteaks.com_LOOP_11NoneNoneNone
49tier_32.contentgate.cam1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
50tier_3promorepublic.com1Onlinenic IncLIA.NS.CLOUDFLARE.COMPromoRepublic Oy
51tier_3wayfair.com1MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
52tier_3cehappear.fun1Dynadot LLCAIDEN.NS.CLOUDFLARE.COMNone
53tier_3om.forgeofempires.com1INWX GmbH & Co. KGNS.INWX.DEREDACTED FOR PRIVACY
54tier_3americanlisted.com1ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
55tier_3dollartree.com1Network Solutions, LLCA1-230.AKAM.NETNone
56tier_33.contentgate.cam1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
57tier_3famous-smoke.com1GoDaddy.com, LLCIGOR.NS.CLOUDFLARE.COMFamous Smoke Shop-PA Inc
58tier_3appliancesconnection.com1GoDaddy.com, LLCNS67.DOMAINCONTROL.COMDomains By Proxy, LLC
59tier_3bestsecretflirt.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
2207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
3207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_118nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
7206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
882.192.82.228AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
937.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2154nannan
1134.231.10.22AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_299ec2-34-231-10-22.compute-1.amazonaws.comnan
12100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_311pool-100-37-135-2.nycmny.fios.verizon.netnan
1335.227.211.136Kansas CityMissouriAS15169 Google LLC64121United Statestier_246136.211.227.35.bc.googleusercontent.comTrue
1434.95.127.121Kansas CityMissouriAS15169 Google LLC64121United Statestier_246121.127.95.34.bc.googleusercontent.comTrue
15198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_31nannan
1635.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_240240.61.209.35.bc.googleusercontent.comnan
17192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_38rd.bizrate.comnan
18178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_33nannan
1918.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_231ec2-18-235-67-128.compute-1.amazonaws.comnan
20198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_231nannan
21104.18.107.83San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_330nanTrue
2254.197.172.17AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_223ec2-54-197-172-17.compute-1.amazonaws.comnan
2367.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_221nannan
2434.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_221ec2-34-197-176-2.compute-1.amazonaws.comnan
2552.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_221ec2-52-72-29-7.compute-1.amazonaws.comnan
26173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21818.65.c0ad.ip4.static.sl-reverse.comnan
2754.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_217ec2-54-208-107-202.compute-1.amazonaws.comnan
28104.18.108.83San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_316nanTrue
2954.156.19.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_216ec2-54-156-19-202.compute-1.amazonaws.comnan
30104.18.107.83San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_330nanTrue
3167.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_321nannan
3235.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_319123.171.246.35.bc.googleusercontent.comnan
33104.18.108.83San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_316nanTrue
34100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_311pool-100-37-135-2.nycmny.fios.verizon.netnan
35192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_38rd.bizrate.comnan
3664.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_36nannan
3767.207.80.24North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
38167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
3923.44.210.223EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_33a23-44-210-223.deploy.static.akamaitechnologies.comnan
40104.77.220.218New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_33a104-77-220-218.deploy.static.akamaitechnologies.comnan
41162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_33nannan
42198.199.66.189North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
43178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_33nannan
4452.73.87.228AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-52-73-87-228.compute-1.amazonaws.comnan
4552.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-52-73-153-209.compute-1.amazonaws.comnan
4623.73.227.48EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_33a23-73-227-48.deploy.static.akamaitechnologies.comnan
47157.245.84.7North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
4834.192.40.54AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-34-192-40-54.compute-1.amazonaws.comnan
49104.21.95.133San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
5013.226.38.30NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-13-226-38-30.ewr53.r.cloudfront.netnan
51104.26.5.91San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
52184.87.65.240NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a184-87-65-240.deploy.static.akamaitechnologies.comnan
53167.172.139.120North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
54198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_31nannan
55172.67.72.21San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5623.41.168.201EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-41-168-201.deploy.static.akamaitechnologies.comnan
5799.84.189.25WashingtonWashington, D.C.AS16509 Amazon.com, Inc.20045United Statestier_31server-99-84-189-25.iad89.r.cloudfront.netnan
58212.48.98.37HamburgHamburgAS8893 Artfiles New Media GmbH20038Germanytier_31nannan
5913.226.38.104NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-13-226-38-104.ewr53.r.cloudfront.netnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website