Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
024524977601572021-02-20207.244.67.215Android
tierdomaincountregistrarname_serversorg
0tier_1forrealzpiratebay.org1Biglizarddomains.com LLCNS1.COMMONMX.COMNone
1tier_1ecomatt.co1GoDaddy.com, LLCns2.commonmx.comNone
2tier_1720pizle.co1GoDaddy.com, LLCns2.commonmx.comNone
3tier_1dudedigitalcodes.com1Chipshot Domains LLCNS1.COMMONMX.COMNone
4tier_1baicung.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
5tier_1desigay.org1Beartrapdomains.com LLCNS1.COMMONMX.COMNone
6tier_1chagford-accom.co.uk1Virtua Drug Ltd t/a autoBackorder [Tag = AUTOBACKORDER]nNone
7tier_1davmodeldgp.org1Domainamania.com LLCNS1.COMMONMX.COMNone
8tier_1fueledup.co1Communigal Communication Ltdns2.commonmx.comNone
9tier_1cannalegit.co1Communigal Communication Ltdns2.commonmx.comNone
10tier_22893.wcitianka.com70GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
11tier_2awakeningsco.com69GoDaddy Online Services Cayman Islands LTDHUGH.NS.CLOUDFLARE.COMNone
12tier_2dprtb.com431API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
13tier_2bradamante-per.com26Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
14tier_2get.popplunder.com26NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
15tier_2trustedpush.com25NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
16tier_2win1.trustedpush.com22NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
17tier_2alfik-fik.com19Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
18tier_2win2.trustedpush.com13NoneNoneNone
19tier_2btpnative.com81API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
20tier_3dprtb.com551API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
21tier_3b.funmapd.xyz23Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
22tier_3m.fastspotb.xyz16Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
23tier_3b.gladspaceplane.xyz14Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
24tier_3storystudio.sfgate.com12CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
25tier_3win3.trustedpush.com11NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
26tier_3b.delightcmain.xyz11Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
27tier_3btpnative.com111API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
28tier_3win2.trustedpush.com9NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
29tier_3b.meeryslotspin.xyz9Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
ipcityregionorgpostalcountry_nametiercountanycasthostname
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_128nannan
1207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_126nannan
2207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_125nannan
3207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nannan
4206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_119nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
737.48.65.150SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_18nannan
837.48.65.149SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_14nannan
9104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_14nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_270nannan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_366nannan
12104.18.2.198San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_246Truenan
1334.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_226nanec2-34-199-180-187.compute-1.amazonaws.com
14104.18.3.198San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_223Truenan
1534.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_223nanec2-34-200-146-95.compute-1.amazonaws.com
1654.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_222nanec2-54-84-27-165.compute-1.amazonaws.com
1713.225.218.47New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_218nanserver-13-225-218-47.jfk51.r.cloudfront.net
18204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_217nan204.44.79.214.static.quadranet.com
1913.225.218.79New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_216nanserver-13-225-218-79.jfk51.r.cloudfront.net
20209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_366nannan
21104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_328Truenan
22100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_318nanpool-100-37-135-2.nycmny.fios.verizon.net
2398.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_317nannan
24104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_315Truenan
25104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313Truenan
26104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311Truenan
27104.18.79.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36Truenan
2813.225.218.113New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_34nanserver-13-225-218-113.jfk51.r.cloudfront.net
29104.21.95.173San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32Truenan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website