Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0323355002021-04-19185.53.177.73Safari
tierdomaincountregistrarname_serversorg
0tier_11link.in1TLD Registrar Solutions Ltd.ns1.parkingcrew.netNone
1tier_1achannelnews.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
2tier_1forexplace.net1Sea Wasp, LLCNS1.BIDOPARKING.COMSavvy Investments, LLC Privacy ID# 858086
3tier_1abram.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
4tier_1vasileios.gr1NoneNoneNone
5tier_1ad-aware.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
6tier_1a-l.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
7tier_1a1signs.ca1NoneNoneNone
8tier_11844.ca1NoneNoneNone
9tier_13500.ca1dot-ca-registry.ca (Burmac Business Systems Ltd)NoneNone
10tier_2katie.v4.omgtnc.com9PSI-USA, Inc. dba Domain RobotNS-1133.AWSDNS-13.ORGNone
11tier_2recode.pw4GANDI SASNS-1611.AWSDNS-09.CO.UKPPCBUZZ
12tier_2us.redirectbuzz.club4Gandi SASns-2.awsdns-00.comPPCBUZZ
13tier_2paid.outbrain.com4Network Solutions, LLCDNS1.P07.NSONE.NETNone
14tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
15tier_2gamers-net.com2GANDI SASNS-1298.AWSDNS-34.ORGPPCBUZZ
16tier_2carsnspeed.net1GANDI SASNS-1120.AWSDNS-12.ORGPPCBUZZ
17tier_2click.clkepd.com1NoneNoneNone
18tier_2redirect.viglink.com1Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
19tier_2link.sylikes.com1NoneNoneNone
20tier_2rd.bizrate.com1NoneNoneNone
21tier_2rd.connexity.net1NoneNoneNone
22tier_2api.kelkoogroup.net1NoneNoneNone
23tier_2us-go.kelkoogroup.net1NoneNoneNone
24tier_2click.linksynergy.com1CSC CORPORATE DOMAINS, INC.DNS1.P09.NSONE.NETRakuten Marketing
25tier_2newsinformer.net1GANDI SASNS-1092.AWSDNS-08.ORGPPCBUZZ
26tier_3healthgrades.com4Amazon Registrar, Inc.NS-1102.AWSDNS-09.ORGWhois Privacy Service
27tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
28tier_3searchingmagnified.com1PDR Ltd. d/b/a PublicDomainRegistry.comNS1004.ZTOMY.COMPrivacy Protect, LLC (PrivacyProtect.org)
29tier_3bostonproper.com1Amazon Registrar, Inc.NS-117.AWSDNS-14.COMWhois Privacy Service
30tier_3hypable.com1GoDaddy.com, LLCLILY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
31tier_3splendid.com1GoDaddy.com, LLCNS19.DOMAINCONTROL.COMDomains By Proxy, LLC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0104.247.81.73WyandotteMichiganAS206834 Team Internet AG48192United Statestier_19nannan
1141.8.224.130DallasTexasAS40034 Confluence Networks Inc75270United Statestier_11nannan
23.220.46.255AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-3-220-46-255.compute-1.amazonaws.comnan
366.232.112.79TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2466-232-112-79.static.hvvc.usnan
4151.101.202.132WashingtonWashington, D.C.AS54113 Fastly20045United Statestier_23nannan
566.232.112.74TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2266-232-112-74.static.hvvc.usnan
654.197.172.17AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-54-197-172-17.compute-1.amazonaws.comnan
7192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_22rd.bizrate.comnan
866.232.112.85TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2266-232-112-85.static.hvvc.usnan
966.232.112.82TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2266-232-112-82.static.hvvc.usnan
1066.232.112.90TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2166-232-112-90.static.hvvc.usnan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_21nannan
1234.195.100.186AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-34-195-100-186.compute-1.amazonaws.comnan
13192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_21rd.connexity.netnan
1452.45.77.217AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-52-45-77-217.compute-1.amazonaws.comnan
1599.84.114.64NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_21server-99-84-114-64.ewr52.r.cloudfront.netnan
1695.211.116.27AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_21dc1-ecs-pub-go-vip.kelkoo.comnan
1735.212.119.88WashingtonWashington, D.C.AS15169 Google LLC20045United Statestier_2188.119.212.35.bc.googleusercontent.comnan
1866.232.112.86TampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_2166-232-112-86.static.hvvc.usnan
19151.101.250.132AshburnVirginiaAS54113 Fastly20149United Statestier_21nannan
20143.204.148.2NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_34server-143-204-148-2.ewr52.r.cloudfront.netnan
21162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
22208.91.196.4DallasTexasAS40034 Confluence Networks Inc75270United Statestier_31nannan
2313.33.46.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-13-33-46-107.ewr52.r.cloudfront.netnan
24172.67.74.218San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
25151.101.1.124San FranciscoCaliforniaAS54113 Fastly94107United Statestier_31nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website