Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0222145002021-04-12185.53.177.73Safari
tierdomaincountregistrarname_serversorg
0tier_11link.in1TLD Registrar Solutions Ltd.ns1.parkingcrew.netNone
1tier_1achannelnews.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
2tier_1abram.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
3tier_1vasileios.gr1NoneNoneNone
4tier_1ad-aware.ca1NoneNoneNone
5tier_1a-l.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
6tier_1a1signs.ca1NoneNoneNone
7tier_11844.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
8tier_13500.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
9tier_2katie.v4.omgtnc.com9PSI-USA, Inc. dba Domain RobotNS-1133.AWSDNS-13.ORGNone
10tier_2nizephoros-pom.com4Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
11tier_2managerformula.com4NoneNoneNone
12tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
13tier_2redirect.viglink.com2Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
14tier_2link.sylikes.com2MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
15tier_2rd.bizrate.com2NoneNoneNone
16tier_2rd.connexity.net2NoneNoneNone
17tier_3s3.amazonaws.com4MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
18tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
19tier_3rpa21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
20tier_3venus.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMVenus Fashion, Inc.
21tier_3theory.com1CSC CORPORATE DOMAINS, INC.NS0.DNSMADEEASY.COMTheory LLC
ipcityregionorgpostalcountry_nametiercounthostname
0104.247.81.73WyandotteMichiganAS206834 Team Internet AG48192United Statestier_19nan
152.45.77.217AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-52-45-77-217.compute-1.amazonaws.com
2192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_24nan
334.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-34-207-43-7.compute-1.amazonaws.com
4172.232.19.177NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_22a172-232-19-177.deploy.static.akamaitechnologies.com
5172.232.19.136NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_22a172-232-19-136.deploy.static.akamaitechnologies.com
652.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-52-205-177-114.compute-1.amazonaws.com
734.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-34-225-128-119.compute-1.amazonaws.com
8192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_22rd.connexity.net
934.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-34-197-176-2.compute-1.amazonaws.com
1052.22.6.66AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-52-22-6-66.compute-1.amazonaws.com
1152.206.108.38AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-52-206-108-38.compute-1.amazonaws.com
12162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_33nan
1352.217.74.38AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.com
1452.216.130.37AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.com
1552.216.113.197AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.com
1623.33.103.173New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31a23-33-103-173.deploy.static.akamaitechnologies.com
1723.33.111.200New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31a23-33-111-200.deploy.static.akamaitechnologies.com

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website