Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0250250752102020-09-28207.244.67.215Chrome
tierdomaincountregistrarname_serversorg
0tier_1sengoku-expo.net1Soldierofonedomains.com, LLCNS1.DNSNUTS.COMNone
1tier_1socordas.com1SNAPNAMES 18, LLCNS1.DNSNUTS.COMNone
2tier_1heroes-strategie.com1One Putt, LLCNS1.DNSNUTS.COMNone
3tier_1pctclinic.com1Noteworthydomains, LLCNS1.DNSNUTS.COMNone
4tier_1anjomanebazaryaban.com1Free Drop Zone LLCNS1.DNSNUTS.COMNone
5tier_1templatesuplex.com1Skykomishdomains.com LLCNS1.DNSNUTS.COMNone
6tier_1mypinkdiary.net1Namefinger.com LLCNS1.DNSNUTS.COMNone
7tier_1woolstonrovers.com1SNAPNAMES 17, LLCNS1.DNSNUTS.COMNone
8tier_1streamingbb.net1Domainshop LLCNS1.DNSNUTS.COMNone
9tier_1bearmythology.net1Allearthdomains.com LLCNS1.DNSNUTS.COMNone
10tier_2click.expmediadirect.com92NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
11tier_2dprtb.com49GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
12tier_2conger-required.icu43Key-Systems GmbHNS-1416.AWSDNS-49.ORGc/o whoisproxy.com
13tier_2rqhere.com40NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_2usd.theodorus-flo.com25Amazon Registrar, Inc.NS-1307.AWSDNS-35.ORGWhois Privacy Service
15tier_2usa.theodorus-flo.com23Amazon Registrar, Inc.NS-1307.AWSDNS-35.ORGWhois Privacy Service
16tier_2btpnative.com9GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
17tier_2infopicked.com9NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
18tier_2p274639.infopicked.com9NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
19tier_210.trackints.com8NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
20tier_3maxforceketos.com41NoneNoneNone
21tier_3pokertimes.xyz40GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
22tier_3healthcarezone.info26GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
23tier_31496.wcitianka.com11UNIREGISTRAR CORPNS-1096.AWSDNS-09.ORGNone
24tier_3wix.com8GoDaddy.com, LLCNS1.P14.DYNECT.NETWix.com, LTD.
25tier_3searchfrequently.com8GoDaddy.com, LLCNEIL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
26tier_37newsreport.info7GoDaddy.com, LLCNS1.DIGITALOCEAN.COMNone
27tier_3americanlisted.com4ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
28tier_3s3.amazonaws.com4MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
29tier_3amazon.force.com2NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_137nan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_133nan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_132nan
3207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_123nan
482.192.82.225SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_19nan
582.192.82.226SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_18nan
637.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_17nan
737.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nan
882.192.82.227SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_15nan
937.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_292nan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_258nan
1234.232.27.114Virginia BeachVirginiaAS14618 Amazon.com, Inc.23457United Statestier_243ec2-34-232-27-114.compute-1.amazonaws.com
13167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_240nan
1452.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23457United Statestier_230ec2-52-205-210-89.compute-1.amazonaws.com
1554.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23457United Statestier_224ec2-54-225-132-253.compute-1.amazonaws.com
16173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21818.65.c0ad.ip4.static.sl-reverse.com
17108.168.193.185DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_28b9.c1.a86c.ip4.static.sl-reverse.com
18198.54.112.216Virginia BeachVirginiaAS22612 Namecheap, Inc.23458United Statestier_311nan
19173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_26nan
20172.67.166.252New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_318nan
21104.27.129.245Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_317nan
22104.27.159.218Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_317nan
23172.67.159.147New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_315nan
24104.27.153.54Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_311nan
25198.54.112.216Virginia BeachVirginiaAS22612 Namecheap, Inc.23458United Statestier_311nan
26172.67.140.152New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_310nan
2735.227.233.104Kansas CityMissouriAS15169 Google LLC64121United Statestier_39104.233.227.35.bc.googleusercontent.com
28104.27.128.245Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_38nan
29161.35.41.39LondonEnglandAS14061 DigitalOcean, LLCEC1AUnited Kingdomtier_37nan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website