Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02782779840132021-04-16185.107.56.199Iphone
tierdomaincountregistrarname_serversorg
0tier_1erotop.info1Dynadot, LLCNS1.COMMONMX.COMNone
1tier_1best-ga.me1Dynadot, LLCNoneNone
2tier_1aurbataao.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159179997
3tier_1atransmissionclinic.com1! #1 Host Canada, Inc.NS1.COMMONMX.COMNone
4tier_1skymaps.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
5tier_1apstc.org1Columbianames.com LLCNS1.COMMONMX.COMStatutory Masking Enabled
6tier_1bankersadda.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1bicoholics.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158852663
8tier_1massagista.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1alinaplugaru.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2aristo-hag.com79Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2btpnav.com711API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2click.expmediadirect.com60NoneNoneNone
13tier_2atnpx.com60GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
14tier_2api.quotes.com27Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
15tier_2changeslots.com27Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
16tier_2api.apptap.com20Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
17tier_2redirect.viglink.com20Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
18tier_2link.sylikes.com20MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
19tier_2api.mplayit.com19Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
20tier_2rtbstream.com181API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
21tier_2rd.bizrate.com16NoneNoneNone
22tier_2rd.connexity.net16MarkMonitor Inc.NS-1190.AWSDNS-20.ORGNone
23tier_2c.clickprotects.com12GoDaddy.com, LLCNS63.DOMAINCONTROL.COMDomains By Proxy, LLC
24tier_211165151.addotnet.com12GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
25tier_2geo.itunes.apple.com12CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
26tier_2itunes.apple.com12CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
27tier_2ad.doubleclick.net12NoneNoneNone
28tier_2exporimy.com7GoDaddy.com, LLCNS-1145.AWSDNS-15.ORGDomains By Proxy, LLC
29tier_2sorrectionki.space7NoneNoneNone
30tier_3kbb.com44CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
31tier_3bestappland.me34NoneNoneNone
32tier_3theconnectvpn.com27DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
33tier_3robogarden.io16GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
34tier_3music.apple.com12CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
35tier_3storystudio.sfgate.com9CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
36tier_3rd.bizrate.com9MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
37tier_3tackis.xyz7NoneNoneNone
38tier_3wayfair.com3MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
39tier_3patpat.sjv.io2GANDI SASNS-545.AWSDNS-04.NETNone
40tier_3wayfair.com_LOOP_12NoneNoneNone
41tier_3patpat.sjv.io_LOOP_12NoneNoneNone
42tier_3ww38.quickbooksx.com1Key-Systems GmbHNS1.ABOVE.COMc/o whoisproxy.com
43tier_3aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGNone
44tier_3edureka.co1Network Solutions, LLCns-1218.awsdns-24.orgkapil
45tier_3atnpx.com1GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
46tier_3dollartree.com1Network Solutions, LLCA1-230.AKAM.NETNone
47tier_3overstock.com1MarkMonitor, Inc.DNS1.P01.NSONE.NETOverstock.com, Inc - TMA606142
48tier_3adameve.com1Network Solutions, LLCA1-75.AKAM.NETNone
49tier_3skechers.com1NoneNoneNone
50tier_3appliancesconnection.com1GoDaddy.com, LLCNS67.DOMAINCONTROL.COMDomains By Proxy, LLC
51tier_3ads.midwayusa.com1GoDaddy.com, LLCNS-1486.AWSDNS-57.ORGMidwayUSA
52tier_3frontgate.com1Network Solutions, LLCNS1.HSN.NETCornerstone Brands, Inc.
53tier_3bestbody.s3.amazonaws.com1MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
54tier_31800petmeds.com1GoDaddy.com, LLCDNS1.P03.NSONE.NETPETMED EXPRESS, INC.
55tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETMacy's Systems and Technology, Inc.
56tier_3ram21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
57tier_3search.discoverweb.com1GoDaddy.com, LLCNINA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
58tier_3fanatics.com1NoneNoneNone
59tier_3filter.onwardclick.com1NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_125nannan
2207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_117nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_116nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
874.63.241.30DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1530-241-63-74.static.reverse.lstn.netnan
937.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_291nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_260nannan
12192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_39rd.bizrate.comnan
13104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
145.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_227nannan
1534.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_227ec2-34-207-32-33.compute-1.amazonaws.comnan
16209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_226nannan
17104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_223nanTrue
1854.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-208-107-202.compute-1.amazonaws.comnan
1918.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-18-235-67-128.compute-1.amazonaws.comnan
2034.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_219ec2-34-197-176-2.compute-1.amazonaws.comnan
213.224.109.140AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_218ec2-3-224-109-140.compute-1.amazonaws.comnan
2252.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_217ec2-52-72-29-7.compute-1.amazonaws.comnan
23192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_216rd.connexity.netnan
2423.43.252.68NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_212a23-43-252-68.deploy.static.akamaitechnologies.comnan
2552.21.176.105AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_211ec2-52-21-176-105.compute-1.amazonaws.comnan
2654.84.4.127AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_211ec2-54-84-4-127.compute-1.amazonaws.comnan
27184.85.6.44NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_210a184-85-6-44.deploy.static.akamaitechnologies.comnan
2854.197.172.17AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-54-197-172-17.compute-1.amazonaws.comnan
29204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_29204.44.79.214.static.quadranet.comnan
3023.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_344a23-44-217-143.deploy.static.akamaitechnologies.comnan
31142.93.4.215North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_334nannan
32100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_317pool-100-37-135-2.nycmny.fios.verizon.netnan
33104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_315nanTrue
34104.21.91.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314nanTrue
35172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313nanTrue
36151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_39nanTrue
37192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_39rd.bizrate.comnan
38104.21.65.93San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
3923.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a23-41-189-99.deploy.static.akamaitechnologies.comnan
4035.227.211.136Kansas CityMissouriAS15169 Google LLC64121United Statestier_32136.211.227.35.bc.googleusercontent.comTrue
41185.53.179.28MunichBavariaAS61969 Team Internet AG80331Germanytier_31nannan
4254.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-208-107-202.compute-1.amazonaws.comnan
4354.192.100.33NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-54-192-100-33.ewr53.r.cloudfront.netnan
44104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
4523.73.233.19EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-73-233-19.deploy.static.akamaitechnologies.comnan
46172.67.189.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
47104.77.221.88New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31a104-77-221-88.deploy.static.akamaitechnologies.comnan
48184.85.24.16NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-85-24-16.deploy.static.akamaitechnologies.comnan
49104.16.189.137San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5024.157.42.211New York CityNew YorkAS6128 Cablevision Systems Corp.10004United Statestier_31189d2ad3.cst.lightpath.netnan
51104.102.136.83EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a104-102-136-83.deploy.static.akamaitechnologies.comnan
52184.87.71.113NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-87-71-113.deploy.static.akamaitechnologies.comnan
5352.217.44.156AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1-w.amazonaws.comnan
54104.16.135.104San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
55104.77.220.218New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31a104-77-220-218.deploy.static.akamaitechnologies.comnan
56162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_31nannan
57172.67.144.251San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
58184.87.65.240NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-87-65-240.deploy.static.akamaitechnologies.comnan
59172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website