Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0393754012021-04-14185.53.177.73Chrome
tierdomaincountregistrarname_serversorg
0tier_11link.in1TLD Registrar Solutions Ltd.ns1.parkingcrew.netNone
1tier_1bitcoinclub.pl1Aftermarket.pl LimitednNone
2tier_1ggogle.dk1Nonens1.parkingcrew.netNone
3tier_1giogle.dk1Nonens1.parkingcrew.netNone
4tier_1mcinternet.dk1Nonens1.parkingcrew.netNone
5tier_1nordera.dk1Nonens1.parkingcrew.netNone
6tier_1hairdesign.dk1Nonens1.parkingcrew.netNone
7tier_1gooogle.dk1Nonens1.parkingcrew.netNone
8tier_1leasplan.dk1Nonens1.parkingcrew.netNone
9tier_1patientvejledningen.dk1Nonens1.parkingcrew.netNone
10tier_2katie.v4.omgtnc.com9PSI-USA, Inc. dba Domain RobotNS-1133.AWSDNS-13.ORGNone
11tier_2recode.pw3GANDI SASNS-1611.AWSDNS-09.CO.UKPPCBUZZ
12tier_2us.redirectbuzz.club2Gandi SASns-2.awsdns-00.comPPCBUZZ
13tier_2technoblogs.net2GANDI SASNS-1196.AWSDNS-21.ORGPPCBUZZ
14tier_2paid.outbrain.com2Network Solutions, LLCDNS1.P07.NSONE.NETNone
15tier_2clk.rtpdn12.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
16tier_2traff0121.com1NAMECHEAP INCHANS.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
17tier_2contentgate.art1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
18tier_20.contentgate.art1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
19tier_21.contentgate.art1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
20tier_22.contentgate.art1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
21tier_23.contentgate.art1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
22tier_2trfktunnel.com1NAMECHEAP INCDAVE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
23tier_2betalonflamechan.com1URL SOLUTIONS INC.NS-1305.AWSDNS-35.ORGGLOBAL DOMAIN PRIVACY SERVICES INC
24tier_2t.sslrt4.com1NAMECHEAP INCNS-1092.AWSDNS-08.ORGPrivacy service provided by Withheld for Privacy ehf
25tier_2batores-dimineer.com1Amazon Registrar, Inc.NS-111.AWSDNS-13.COMWhois Privacy Service
26tier_2trkppc.com1NAMECHEAP INCPDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
27tier_2capitaloneshopping.sjv.io1GANDI SASNS-545.AWSDNS-04.NETNone
28tier_2ojrq.net1GANDI SASNS-1151.AWSDNS-15.ORGImpact Radius
29tier_2capitaloneshopping.sjv.io_LOOP_11NoneNoneNone
30tier_3mergerinvesting.com2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
31tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
32tier_3auth.bitbay.net1NAMECHEAP INCEMMA.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
33tier_3shop.threesbrewing.com1NoneNoneNone
34tier_3crutchfield.com1Domain.com, LLCNS1.CRUTCHFIELD.COMREDACTED FOR PRIVACY
35tier_3capitaloneshopping.com1CSC CORPORATE DOMAINS, INC.IVY.NS.CLOUDFLARE.COMCapital One Services, LLC
36tier_3surveystarz.com1GoDaddy.com, LLCNS13.DOMAINCONTROL.COMDomains By Proxy, LLC
37tier_3dropped-click.com1NAMECHEAP INCINES.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0104.247.81.73WyandotteMichiganAS206834 Team Internet AG48192United Statestier_19nannan
1185.253.212.22WarsawMazoviaAS48707 Marcin Waligorski Greener00-010Polandtier_11nannan
252.45.77.217AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-52-45-77-217.compute-1.amazonaws.comnan
3178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_25nannan
466.232.112.78TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_23nannan
566.232.112.72TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2266-232-112-72.static.hvvc.usnan
666.232.112.85TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2266-232-112-85.static.hvvc.usnan
7199.232.66.132WashingtonWashington, D.C.AS54113 Fastly20045United Statestier_22nannan
888.99.101.106Hohen NeuendorfBrandenburgAS24940 Hetzner Online GmbH16540Germanytier_22static.106.101.99.88.clients.your-server.denan
918.210.103.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-18-210-103-13.compute-1.amazonaws.comnan
103.220.46.255AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-3-220-46-255.compute-1.amazonaws.comnan
11173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_21nannan
12139.45.197.239AmsterdamNorth HollandAS9002 RETN Limited1012Netherlandstier_21nannan
1335.227.247.224Kansas CityMissouriAS15169 Google LLC64121United Statestier_21224.247.227.35.bc.googleusercontent.comTrue
1435.227.211.136Kansas CityMissouriAS15169 Google LLC64121United Statestier_21136.211.227.35.bc.googleusercontent.comTrue
1534.95.127.121Kansas CityMissouriAS15169 Google LLC64121United Statestier_21121.127.95.34.bc.googleusercontent.comTrue
16100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_21pool-100-37-135-2.nycmny.fios.verizon.netnan
17169.63.237.195DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21c3.ed.3fa9.ip4.static.sl-reverse.comnan
1845.55.189.248CliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_32nannan
19162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
20104.18.5.135San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
2123.227.38.74OttawaOntarioAS13335 Cloudflare, Inc.K2PCanadatier_31nanTrue
22205.196.12.74HollymeadVirginiaAS54391 Crutchfield New Media LLC22911United Statestier_31www.crutchfield.comnan
23104.18.16.24San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
24165.227.96.45CliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_31109327.cloudwaysapps.comnan
2575.126.45.196DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_31c4.2d.7e4b.ip4.static.sl-reverse.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website