Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0343456012021-04-16185.53.177.73Safari
tierdomaincountregistrarname_serversorg
0tier_1aevangelism.org1GoDaddy.com, LLCNS1.PARKINGCREW.NETNone
1tier_1elitetrader.org11API GmbHNS1.PARKINGCREW.NET['adaspect media UG haftungsbeschraenkt', 'REDACTED FOR PRIVACY']
2tier_1420rx.org1GoDaddy.com, LLCNS1.PARKINGCREW.NETCTI Holdings Inc.
3tier_1canadatrips.org1Epik Inc.NS1.PARKINGCREW.NETHunley Media Group LLC
4tier_1cellphones.org1Moniker Online Services LLCNS1.FASTPARK.NETMoniker Privacy Services
5tier_1beingme.org1Domain.com, LLCNS1.PARKINGCREW.NET['Glocal Commerce Limited', 'REDACTED FOR PRIVACY']
6tier_1booking-flights.org1INWX GmbH & Co. KGNS1.PARKINGCREW.NET-
7tier_1bihar.org1Dynadot, LLCNS1.PARKINGCREW.NETNone
8tier_2katie.v4.omgtnc.com8PSI-USA, Inc. dba Domain RobotNS-1133.AWSDNS-13.ORGNone
9tier_2rd.bizrate.com4MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
10tier_2rd.connexity.net4NoneNoneNone
11tier_2aristo-hag.com3Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
13tier_2r.lnk8j7.com21&1 IONOS SENS-1314.AWSDNS-36.ORG1&1 Internet Limited
14tier_2v6ur9n22r9.execute-api.us-east-1.amazonaws.com2NoneNoneNone
15tier_2link.sylikes.com2NoneNoneNone
16tier_2noclick.connexity.com2NoneNoneNone
17tier_2trak.today-trip.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
18tier_2wirtgage-proxing.icu1Key-Systems GmbHNS-1046.AWSDNS-02.ORGc/o whoisproxy.com
19tier_2secureconv-ec.com1Key-Systems GmbHNS-1437.AWSDNS-51.ORGc/o whoisproxy.com
20tier_2patpat.sjv.io1GANDI SASNS-545.AWSDNS-04.NETNone
21tier_2patpat.com1ENOM, INC.GINA.NS.CLOUDFLARE.COMWhois Privacy Protection Service, Inc.
22tier_2tr.trackingsys.tech1DonDominio (SCIP)NS1.DONDOMINIO.COMSoluciones Corporativas IP, c/o Whois Proxy
23tier_2zen.affiliateland.io1NAMECHEAP INCALINA.NS.CLOUDFLARE.COMNone
24tier_2bridge.lga1.ap01.net1MarkMonitor, Inc.A1-230.AKAM.NETDNStination Inc.
25tier_2298126900.lga1.ampverified.com1NoneNoneNone
26tier_2clixtrac.com1NAMECHEAP INCNS1.CLIXTRAC.COMWhoisGuard, Inc.
27tier_2secure.adnxs.com1MarkMonitor Inc.NS1.GSLB.COMNone
28tier_3blair.com2CSC CORPORATE DOMAINS, INC.NS-1237.AWSDNS-26.ORGBluestem Brands, Inc.
29tier_3wayfair.com2MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
30tier_3us.patpat.com1ENOM, INC.GINA.NS.CLOUDFLARE.COMWhois Privacy Protection Service, Inc.
31tier_3loadfree-bestheavilyfile.best1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
32tier_3ram21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
33tier_3visitmusiccity.com1GoDaddy.com, LLCNS-1504.AWSDNS-60.ORGNashville Convention & Visitors Corp.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0104.247.81.73WyandotteMichiganAS206834 Team Internet AG48192United Statestier_18nannan
1192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_26rd.bizrate.comnan
23.220.46.255AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-3-220-46-255.compute-1.amazonaws.comnan
3192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_24rd.connexity.netnan
434.231.10.22AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-34-231-10-22.compute-1.amazonaws.comnan
552.45.77.217AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-52-45-77-217.compute-1.amazonaws.comnan
613.226.38.110NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_22server-13-226-38-110.ewr53.r.cloudfront.netnan
718.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-18-235-67-128.compute-1.amazonaws.comnan
8192.138.218.215SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_22noclick.connexity.comnan
9104.218.72.13New York CityNew YorkAS63190 adMarketplace, Inc.10016United Statestier_22nannan
1054.197.172.17AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-54-197-172-17.compute-1.amazonaws.comnan
1135.172.107.150AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-35-172-107-150.compute-1.amazonaws.comnan
1252.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-52-72-29-7.compute-1.amazonaws.comnan
1354.162.253.78AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-54-162-253-78.compute-1.amazonaws.comnan
1435.227.211.136Kansas CityMissouriAS15169 Google LLC64121United Statestier_21136.211.227.35.bc.googleusercontent.comTrue
15104.18.107.83San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
16107.20.106.95AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-107-20-106-95.compute-1.amazonaws.comnan
1752.22.6.66AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-52-22-6-66.compute-1.amazonaws.comnan
18208.100.38.218ChicagoIllinoisAS32748 Steadfast60607United Statestier_21clixtrac.comnan
1968.67.161.206New York CityNew YorkAS29990 AppNexus, Inc10004United Statestier_21798.bm-nginx-loadbalancer.mgmt.nym2.adnexus.netnan
2054.84.4.127AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-54-84-4-127.compute-1.amazonaws.comnan
2123.73.247.49EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_32a23-73-247-49.deploy.static.akamaitechnologies.comnan
2223.39.32.237NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-39-32-237.deploy.static.akamaitechnologies.comnan
23104.18.107.83San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
2452.20.53.118AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-20-53-118.compute-1.amazonaws.comnan
25162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_31nannan
2654.164.213.169AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-164-213-169.compute-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website