Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0190197555002020-11-26207.244.67.215Iphone
tierdomaincountregistrarname_serversorg
0tier_1blessedit.com1SNAPNAMES 29, LLCNS1.DNSNUTS.COMNone
1tier_1deadlysinx.net1Domains of Origin, LLCNS1.DNSNUTS.COMNone
2tier_1ddoba.net1Ripcurl Domains, LLCNS1.DNSNUTS.COMNone
3tier_1film4vn.us1UdomainName.com LLCns2.dnsnuts.comNone
4tier_1johnsonscareers.net1DropWeek.com, LLCNS1.DNSNUTS.COMNone
5tier_1alekseypopovv.net1Namearsenal.com LLCNS1.DNSNUTS.COMNone
6tier_1buam.net1SNAPNAMES 3, LLCNS1.DNSNUTS.COMNone
7tier_1newrf.net1Domainsurgeon.com LLCNS1.DNSNUTS.COMNone
8tier_1codingvideos.net1Namecatch Zone LLCNS1.DNSNUTS.COMNone
9tier_1easybed.nl1EuroDNS S.A.ns1.dnsnuts.comNone
10tier_2sopho-kat.com59Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
11tier_2track.vcdc.com54Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
12tier_2atnpx.com33GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2changeslots.com28Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
14tier_2api.quotes.com27Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
15tier_2ad.doubleclick.net11MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
16tier_261101.click.validclick.net9Safenames LtdNS1.FULLMAILBOX.COMNone
17tier_2infopicked.com8NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
18tier_2go.trackinz.com7NAMECHEAP INCNS-1139.AWSDNS-14.ORGWhoisGuard, Inc.
19tier_2dprtb.com6GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
20tier_3kbb.com33CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
21tier_3theconnectvpn.com28DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
22tier_3track.vcdc.com17Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
23tier_3blog.sfchronicle.com10CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
24tier_3blog.chron.com7CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Newspapers, LLC
25tier_3checkthistime.com7NAMECHEAP INCNS-1262.AWSDNS-29.ORGWhoisGuard, Inc.
26tier_3blog.sfgate.com7CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
27tier_3clk.news-headlines.co3NAMECHEAP INCns-1428.awsdns-50.orgWhoisGuard, Inc.
28tier_3allbestsecureus.com2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
29tier_3alets-system.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_123nan
1207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_121nan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_117nan
3207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_114nan
4185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_18nan
5185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_17nan
637.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_17nan
737.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_17nan
837.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_16nan
937.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nan
1054.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_241ec2-54-225-132-253.compute-1.amazonaws.com
1134.207.32.33Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_228ec2-34-207-32-33.compute-1.amazonaws.com
125.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_227nan
13204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_225204.44.79.214.static.quadranet.com
14104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_220nan
1552.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_219ec2-52-205-210-89.compute-1.amazonaws.com
16173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21618.65.c0ad.ip4.static.sl-reverse.com
1794.130.185.237NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_215static.237.185.130.94.clients.your-server.de
1894.130.186.231NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_215static.231.186.130.94.clients.your-server.de
19144.76.0.242KyivKyiv CityAS24940 Hetzner Online GmbH03027Ukrainetier_213static.242.0.76.144.clients.your-server.de
2023.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_333a23-44-217-143.deploy.static.akamaitechnologies.com
21138.201.252.161GeldernNorth Rhine-WestphaliaAS24940 Hetzner Online GmbH47608Germanytier_316proxy.traffic.club
22151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_314nan
23104.27.186.165San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313nan
2498.129.228.57BrookhavenMississippiAS33070 Rackspace Hosting39601United Statestier_311nan
25104.27.187.165San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_310nan
26138.68.8.221Santa ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_37nan
27172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nan
2864.225.2.103CliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_32nan
29100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.net

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website