Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
017817753401312021-02-20207.244.67.215Safari
tierdomaincountregistrarname_serversorg
0tier_1ecomatt.co1GoDaddy.com, LLCns2.commonmx.comNone
1tier_1720pizle.co1GoDaddy.com, LLCns2.commonmx.comNone
2tier_1dudedigitalcodes.com1Chipshot Domains LLCNS1.COMMONMX.COMNone
3tier_1desigay.org1Beartrapdomains.com LLCNS1.COMMONMX.COMNone
4tier_1gamefirst.me1Dynadot, LLCNoneNone
5tier_1davmodeldgp.org1Domainamania.com LLCNS1.COMMONMX.COMNone
6tier_1fueledup.co1Communigal Communication Ltdns2.commonmx.comNone
7tier_1borno.co1Communigal Communication Ltdns1.commonmx.comNone
8tier_1firmfile.us1Communigal Communication Ltdns2.commonmx.comNone
9tier_1busyghana.com1Hawthornedomains.com LLCNS1.COMMONMX.COMNone
10tier_3dprtb.com521API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
11tier_3careerbuilder.com30CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
12tier_3btpnative.com161API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
13tier_3managerformula.com13NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_3s3.amazonaws.com11MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
15tier_3americanlisted.com2ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
16tier_3squirt.org2NAMECHEAP INCNS5.DNSMADEEASY.COMWhoisGuard, Inc.
17tier_3joblift.com2INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMREDACTED FOR PRIVACY
18tier_3signup.myjobscorner.com1GoDaddy.com, LLCALDO.NS.CLOUDFLARE.COMDomains By Proxy, LLC
19tier_3jobleads.com1united domains AGCRUZ.NS.CLOUDFLARE.COMNone
20tier_2dprtb.com521API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
21tier_21496.wcitianka.com38GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
22tier_2americanlisted.com36ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
23tier_2click.appcast.io36101Domain GRS LtdNS-85.AWSDNS-10.COMNone
24tier_2bradamante-per.com24Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
25tier_2btpnative.com141API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
26tier_2infopicked.com13NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
27tier_2managerformula.com11NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
28tier_2joblift.com4INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMREDACTED FOR PRIVACY
29tier_2click.appcast.io_LOOP_13NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nan
1207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nan
2207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_117nan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_117nan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nan
7206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nan
882.192.82.226AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nan
937.48.65.150SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_13nan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_266nan
1113.225.218.48New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_39server-13-225-218-48.jfk51.r.cloudfront.net
1213.225.218.90New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_39server-13-225-218-90.jfk51.r.cloudfront.net
1323.200.0.41EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_25a23-200-0-41.deploy.static.akamaitechnologies.com
1413.225.218.50New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_37server-13-225-218-50.jfk51.r.cloudfront.net
1513.225.218.25New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_35server-13-225-218-25.jfk51.r.cloudfront.net
1623.200.0.5EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_26a23-200-0-5.deploy.static.akamaitechnologies.com
17100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_34pool-100-37-135-2.nycmny.fios.verizon.net
1852.217.74.182Virginia BeachVirginiaAS16509 Amazon.com, Inc.23452United Statestier_32s3-1.amazonaws.com
1952.216.24.110Virginia BeachVirginiaAS16509 Amazon.com, Inc.23452United Statestier_32s3-1.amazonaws.com
20209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_266nan
21198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_238nan
2235.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_236240.61.209.35.bc.googleusercontent.com
2352.0.220.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_221ec2-52-0-220-89.compute-1.amazonaws.com
2454.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_215ec2-54-84-27-165.compute-1.amazonaws.com
253.234.136.137Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_215ec2-3-234-136-137.compute-1.amazonaws.com
26173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21418.65.c0ad.ip4.static.sl-reverse.com
2734.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_211ec2-34-200-146-95.compute-1.amazonaws.com
2823.200.0.5EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_26a23-200-0-5.deploy.static.akamaitechnologies.com
2923.200.0.41EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_25a23-200-0-41.deploy.static.akamaitechnologies.com

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website