Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
029330313320142021-04-10207.244.67.215Android
tierdomaincountregistrarname_serversorg
0tier_1imle.us1Dynadot LLCns2.commonmx.comNone
1tier_1iamtuhin.co1Communigal Communication Ltdns2.commonmx.comNone
2tier_1channel3000.co1Communigal Communication Ltdns1.commonmx.comNone
3tier_1bcmcon.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1hypersia.co1GoDaddy.com, LLCns2.commonmx.comNone
5tier_1influenciador.net1Shining Star Domains, LLCNS1.COMMONMX.COMNone
6tier_1drsureshshuklachandra.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1asisucedio.co1Communigal Communication Ltdns2.commonmx.comNone
8tier_1avsarangg.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158852301
9tier_1auburnpeople.co1Communigal Communication Ltdns2.commonmx.comNone
10tier_2btpnav.com1111API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aristo-hag.com75Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_2nizephoros-pom.com55Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
13tier_2get.popplunder.com55NoneNoneNone
14tier_2trustedpush.com55NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
15tier_2win1.trustedpush.com54NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
16tier_2win2.trustedpush.com43NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
17tier_2ads35.adtelligent.com36DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
18tier_2dsp35.adtelligent.com36DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
19tier_2aibm1.mysearch.space36NoneNoneNone
20tier_2externals-1953518744.us-east-1.elb.amazonaws.com36MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
21tier_2search.snjsearch.com36GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
22tier_2search-checker.com36Name.com, Inc.BETH.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
23tier_2m.onlineweb.mobi36GoDaddy.com, LLCNoneNone
24tier_2win3.trustedpush.com32NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
25tier_2win4.trustedpush.com18NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
26tier_2click.expmediadirect.com17NameCheap, Inc.NS1.LINODE.COMNone
27tier_2btpnative.com161API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
28tier_22893.rawlexi.com16GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
29tier_2awakeningsco.com16GoDaddy Online Services Cayman Islands LTDHUGH.NS.CLOUDFLARE.COMNone
30tier_3bing.com36MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
31tier_3win5.trustedpush.com16NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
32tier_3storystudio.sfgate.com15CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
33tier_3win4.trustedpush.com14NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
34tier_3win2.trustedpush.com11NoneNoneNone
35tier_3win3.trustedpush.com11NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
36tier_3m.placesiteb.xyz8Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
37tier_3storystudio.mysanantonio.com5CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMThe Hearst Corporation
38tier_3a.dollarsurvey365.online3URL Solutions Inc.CRYSTAL.NS.CLOUDFLARE.COMNone
39tier_3filter.onwardclick.com3NoneNoneNone
40tier_3aarpmedicareplans.com3CSC CORPORATE DOMAINS, INC.EDNS4.ULTRADNS.BIZUnitedHealth Group Incorporated
41tier_3rd.bizrate.com3MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
42tier_3beyourxfriend.com3GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
43tier_3storystudio.chron.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Newspapers, LLC
44tier_3htvnativeadsolutions.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Television Inc.
45tier_3dollarshaveclub.com2GoDaddy.com, LLCNS-1465.AWSDNS-55.ORGDomains By Proxy, LLC
46tier_3b.meeryslotspin.xyz2Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
47tier_3win6.trustedpush.com2NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
48tier_3b.gladspaceplane.xyz2Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
49tier_3m.gladplacespin.xyz2Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
50tier_3moneyfinancegold.com2NameCheap, Inc.ANNA.NS.CLOUDFLARE.COMNone
51tier_3aklief.com2NOM-IQ Ltd dba Com LaudeDNS1.COMLAUDE-DNS.COMGalderma Holding SA
52tier_3thredup.com2GoDaddy.com, LLCMATT.NS.CLOUDFLARE.COMThredUp Inc.
53tier_3b.funmapd.xyz2Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
54tier_3uniqlo.com11API GmbHNS-1415.AWSDNS-48.ORGNone
55tier_3netradioplayer.com1GoDaddy.com, LLCNS41.DOMAINCONTROL.COMDomains By Proxy, LLC
56tier_3m.fastspotb.xyz1Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
57tier_3michael-dowling.com1GoDaddy.com, LLCNS77.DOMAINCONTROL.COMNorthwell Health
58tier_3btpnav.com11API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
59tier_3mbest.aliexpress.com1Alibaba Cloud Computing (Beijing) Co., Ltd.NS1.ALIBABADNS.COMNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_125nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_125nannan
3207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_118nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
5104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
7206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_18nannan
882.192.82.227AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
9185.107.56.197RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_31nannan
1199.84.114.35NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_36server-99-84-114-35.ewr52.r.cloudfront.netnan
1234.199.180.187AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_255ec2-34-199-180-187.compute-1.amazonaws.comnan
1399.84.114.90NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-114-90.ewr52.r.cloudfront.netnan
1499.84.114.87NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_35server-99-84-114-87.ewr52.r.cloudfront.netnan
1599.84.114.98NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_35server-99-84-114-98.ewr52.r.cloudfront.netnan
16209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_236static-42-202-205-209.24shells.netnan
17209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_236static-43-202-205-209.24shells.netnan
1835.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_236ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
19204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_232204.44.79.214.static.quadranet.comnan
20104.21.41.235San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_227nanTrue
2118.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_226ec2-18-235-67-128.compute-1.amazonaws.comnan
2252.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_223ec2-52-72-29-7.compute-1.amazonaws.comnan
23192.241.229.243San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_223nannan
2454.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_223ec2-54-208-107-202.compute-1.amazonaws.comnan
2534.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-34-207-43-7.compute-1.amazonaws.comnan
2652.29.135.45Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_221ec2-52-29-135-45.eu-central-1.compute.amazonaws.comnan
2750.16.173.246AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_221ec2-50-16-173-246.compute-1.amazonaws.comnan
2834.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_221ec2-34-197-176-2.compute-1.amazonaws.comnan
2952.206.108.38AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_220ec2-52-206-108-38.compute-1.amazonaws.comnan
30100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_340pool-100-37-135-2.nycmny.fios.verizon.netnan
3198.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_324nannan
32204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_322a-0001.a-msedge.netTrue
3313.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_314nanTrue
3499.84.114.35NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_36server-99-84-114-35.ewr52.r.cloudfront.netnan
3599.84.114.87NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_35server-99-84-114-87.ewr52.r.cloudfront.netnan
36104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
3799.84.114.98NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_35server-99-84-114-98.ewr52.r.cloudfront.netnan
38104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
39104.18.79.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
40104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
41173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_33nannan
42184.85.16.190NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a184-85-16-190.deploy.static.akamaitechnologies.comnan
43192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33nannan
4445.33.8.244RichardsonTexasAS63949 Linode, LLC75080United Statestier_33li962-244.members.linode.comnan
45151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_33nanTrue
4699.84.114.90NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-114-90.ewr52.r.cloudfront.netnan
47151.101.1.9San FranciscoCaliforniaAS54113 Fastly94107United Statestier_32nanTrue
48104.26.14.226San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
49104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
50104.21.95.173San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
51151.101.194.216San FranciscoCaliforniaAS54113 Fastly94107United Statestier_32nanTrue
5223.201.25.61NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-201-25-61.deploy.static.akamaitechnologies.comnan
5352.20.164.166AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-20-164-166.compute-1.amazonaws.comnan
54209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_31nannan
55104.26.15.226San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
56184.85.14.232NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-85-14-232.deploy.static.akamaitechnologies.comnan
5723.59.250.106NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a23-59-250-106.deploy.static.akamaitechnologies.comnan
58151.101.2.126San FranciscoCaliforniaAS54113 Fastly94107United Statestier_31nanTrue
5952.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-3-4-129.compute-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website