Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
028027510861192021-04-16207.244.67.215Iphone
tierdomaincountregistrarname_serversorg
0tier_1carwashnear.me1Dynadot, LLCNoneNone
1tier_1bautista.me1GoDaddy.com, LLCNoneNone
2tier_1lightnovelcafe.com1Chipshot Domains LLCNS1.COMMONMX.COMNone
3tier_1im7love.com1Cool River Names, LLCNS1.COMMONMX.COMNone
4tier_1kembangqq.me1Dynadot, LLCNoneNone
5tier_1ersazza.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
6tier_1bicicletas.me1Dynadot, LLCNoneNone
7tier_1dnscheck.me1Dynadot, LLCNoneNone
8tier_1chiyou.name1NoneNoneNone
9tier_1f5s.me1Dynadot, LLCNoneNone
10tier_2aristo-hag.com74Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2btpnav.com691API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2click.expmediadirect.com56NoneNoneNone
13tier_2ads35.adtelligent.com38DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
14tier_2dsp35.adtelligent.com38DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
15tier_2aibm1.mysearch.space38NoneNoneNone
16tier_2externals-1953518744.us-east-1.elb.amazonaws.com38MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
17tier_2search.snjsearch.com38GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
18tier_2search-checker.com36Name.com, Inc.BETH.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
19tier_2m.onlineweb.mobi36GoDaddy.com, LLCNoneNone
20tier_2api.quotes.com27Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
21tier_2changeslots.com26Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
22tier_2clk.rtpdn12.com21NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
23tier_2exporimy.com17GoDaddy.com, LLCNS-1145.AWSDNS-15.ORGDomains By Proxy, LLC
24tier_2sorrectionki.space17NoneNoneNone
25tier_2rqhere2.com16NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
26tier_2web-shield-club.com13NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
27tier_263086.click.validclick.net11Safenames LtdNS1.FULLMAILBOX.COMNone
28tier_2apptime.xyz10NAMECHEAP INCPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
29tier_2xml.onwardclick.com6NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
30tier_3bestappland.me40NAMECHEAP INCNoneNone
31tier_3bing.com38MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
32tier_3theconnectvpn.com26DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
33tier_3irl.com18GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
34tier_3tackis.xyz11NamecheapPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
35tier_3storystudio.sfgate.com11CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
36tier_3java.limitedtopoffers.com61&1 IONOS SERORY.NS.CLOUDFLARE.COM1&1 Internet Inc
37tier_3bulley.shop3NAMECHEAP INCDAVID.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
38tier_3bestbody.s3.amazonaws.com3MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
39tier_3apple.com3CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
40tier_3gramp.xyz3NoneNoneNone
41tier_3coolmambo.com2NoneNoneNone
42tier_3noom.com2GoDaddy.com, LLCABBY.NS.CLOUDFLARE.COMWorkSmart Labs, Inc.
43tier_3vpn1aprotectplus.com2Internet Domain Service BS Corp.SETH.NS.CLOUDFLARE.COMWhois Privacy Corp.
44tier_3filter.onwardclick.com2NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
45tier_3jobs.tjx.com1MarkMonitor, Inc.A1-117.AKAM.NETThe TJX Companies
46tier_3thelastpicture.show_LOOP_11NoneNoneNone
47tier_3equinoxadvertising.com1NoneNoneNone
48tier_3chrismoneymaker.com1GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
49tier_3owningland.com1CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Newspapers, LLC
50tier_3vivint.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMVivint
51tier_3eharmony.com1NoneNoneNone
52tier_3stateandliberty.com1GoDaddy.com, LLCNS55.DOMAINCONTROL.COMDomains By Proxy, LLC
53tier_3giftcards.com1NoneNoneNone
54tier_3ww1.survey-smiles.com1Media Elite Holdings LimitedNS1.WOMBATDNS.COMFundacion Privacy Services LTD
55tier_3ram21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
56tier_3ballarddesigns.com_LOOP_21NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_117nannan
5104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
737.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_16nannan
882.192.82.226AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
937.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_279nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_256nannan
12209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_238static-42-202-205-209.24shells.netnan
13209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_238static-43-202-205-209.24shells.netnan
1435.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_238ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
15173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_32nannan
1618.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_227ec2-18-235-67-128.compute-1.amazonaws.comnan
175.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_227nannan
1834.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_226ec2-34-207-32-33.compute-1.amazonaws.comnan
1934.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_226ec2-34-197-176-2.compute-1.amazonaws.comnan
2052.29.135.45Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_223ec2-52-29-135-45.eu-central-1.compute.amazonaws.comnan
21172.67.196.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_223nanTrue
22192.241.228.85San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_223nannan
2352.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-52-72-29-7.compute-1.amazonaws.comnan
2450.16.173.246AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_220ec2-50-16-173-246.compute-1.amazonaws.comnan
2554.210.170.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_218ec2-54-210-170-165.compute-1.amazonaws.comnan
2634.202.14.39AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_217ec2-34-202-14-39.compute-1.amazonaws.comnan
27167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_216nannan
283.125.109.211Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_215ec2-3-125-109-211.eu-central-1.compute.amazonaws.comnan
29192.241.229.243San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_215nannan
30142.93.4.215North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_340nannan
31204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_333a-0001.a-msedge.netTrue
32172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_321nanTrue
33151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_311nanTrue
34104.21.65.93San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
35104.21.91.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
3613.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_35nanTrue
37172.67.189.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
3852.73.87.228AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_35ec2-52-73-87-228.compute-1.amazonaws.comnan
3952.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34ec2-52-73-153-209.compute-1.amazonaws.comnan
40104.21.28.174San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
41157.245.84.7North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
4223.38.172.250NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a23-38-172-250.deploy.static.akamaitechnologies.comnan
4364.91.232.212LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_32host.encontext.comnan
44100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.netnan
45172.67.134.131San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
46157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
47173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_32nannan
48172.67.146.238San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
49104.21.92.190San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
5023.253.31.170ChicagoIllinoisAS19994 Rackspace Hosting60601United Statestier_31nannan
51104.17.0.107San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5252.217.78.100AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1-w.amazonaws.comnan
53104.21.63.48San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5469.16.204.63LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_31host.encontext.comnan
55104.21.25.197San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5692.205.4.117StrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_31ip-92-205-4-117.ip.secureserver.netnan
57167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
5818.191.181.152HilliardOhioAS16509 Amazon.com, Inc.43026United Statestier_31ec2-18-191-181-152.us-east-2.compute.amazonaws.comnan
5952.203.36.44AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-203-36-44.compute-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website