Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02432509000202021-04-19207.244.67.215Safari
tierdomaincountregistrarname_serversorg
0tier_1lynko.co1Communigal Communication Ltdns2.commonmx.comNone
1tier_1jntukresultsdb.com1Domainsofcourse.com LLCNS1.COMMONMX.COMNone
2tier_1grupocoop.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1javweb.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1canadianwind.net1NoneNoneNone
5tier_1dakikpanel.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1abndn.us1Communigal Communication Ltdns1.commonmx.comNone
7tier_1lorieason.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
8tier_1mtiwadawa.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1jasonvalesbigjuicechallenge.com1NoneNoneNone
10tier_2btpnav.com1351API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aristo-hag.com65Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_2nizephoros-pom.com63Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
13tier_21496.rawlexi.com42GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
14tier_2americanlisted.com39ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_2btpnative.com241API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
16tier_2infopicked.com23NAMECHEAP INCNS0.DNSMADEEASY.COMPrivacy service provided by Withheld for Privacy ehf
17tier_2managerformula.com20NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
18tier_29nl.es14NoneNoneNone
19tier_2newre-conversions.clickmeter.com14NoneNoneNone
20tier_2trk.jometer.com14Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
21tier_2api.l5srv.net14GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
22tier_2atnpx.com6GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
23tier_2ads35.adtelligent.com6DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
24tier_2dsp35.adtelligent.com6DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
25tier_2aldb1.mysearch.space6NoneNoneNone
26tier_2externals-1953518744.us-east-1.elb.amazonaws.com6NoneNoneNone
27tier_2search.snjsearch.com6GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
28tier_2ad.doubleclick.net5NoneNoneNone
29tier_2seekallanswrs.com3NameSilo, LLCNS-CLOUD-A1.GOOGLEDOMAINS.COMSee PrivacyGuardian.org
30tier_3irl.com46GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
31tier_3managerformula.com42NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
32tier_3us.tideri.com24united domains AGNS.UDAG.DENone
33tier_3s3.amazonaws.com20NoneNoneNone
34tier_3upward.careers14GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
35tier_3bing.com6NoneNoneNone
36tier_3kbb.com4CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
37tier_3americanlisted.com3ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
38tier_3storystudio.sfgate.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
39tier_3robogarden.io2GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
40tier_3gogreensolar.com1GoDaddy.com, LLCNS37.DOMAINCONTROL.COMGigawatt Inc DBA GoGreenSolar
41tier_3neuvoo.com1NoneNoneNone
42tier_3owningland.com1CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Newspapers, LLC
43tier_3aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
44tier_3promorepublic.com1Onlinenic IncLIA.NS.CLOUDFLARE.COMPromoRepublic Oy
45tier_3hp.com1NoneNoneNone
46tier_3adobe.com1NOM-IQ Ltd dba Com LaudeA1-217.AKAM.NETAdobe Inc.
47tier_3deciem.com_LOOP_11NoneNoneNone
48tier_3nizephoros-pom.com1Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
49tier_3wayfair.com1NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_136nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
4206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_116nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
8185.107.56.198RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
937.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2159nannan
11198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nannan
1235.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
1352.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_237ec2-52-72-29-7.compute-1.amazonaws.comnan
1454.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_237ec2-54-208-107-202.compute-1.amazonaws.comnan
1518.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_231ec2-18-235-67-128.compute-1.amazonaws.comnan
16173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_22418.65.c0ad.ip4.static.sl-reverse.comnan
1734.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_223ec2-34-197-176-2.compute-1.amazonaws.comnan
1867.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_214nannan
1923.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_211ec2-23-21-53-13.compute-1.amazonaws.comnan
2023.200.0.5EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_324a23-200-0-5.deploy.static.akamaitechnologies.comnan
2123.200.0.41EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_318a23-200-0-41.deploy.static.akamaitechnologies.comnan
2223.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-23-21-166-45.compute-1.amazonaws.comnan
2354.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-54-197-247-190.compute-1.amazonaws.comnan
2499.84.114.17NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_26server-99-84-114-17.ewr52.r.cloudfront.netnan
25209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_26static-42-202-205-209.24shells.netnan
26209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_26static-43-202-205-209.24shells.netnan
2735.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_26ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
2899.84.114.25NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_26server-99-84-114-25.ewr52.r.cloudfront.netnan
29104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_25nanTrue
3035.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_324123.171.246.35.bc.googleusercontent.comnan
3123.200.0.5EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_324a23-200-0-5.deploy.static.akamaitechnologies.comnan
3223.200.0.41EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_318a23-200-0-41.deploy.static.akamaitechnologies.comnan
3367.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_314nannan
3452.203.36.44AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_311ec2-52-203-36-44.compute-1.amazonaws.comnan
3564.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_310nannan
3667.207.81.229North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_35nannan
3723.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_34a23-44-217-143.deploy.static.akamaitechnologies.comnan
3854.205.240.192AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34ec2-54-205-240-192.compute-1.amazonaws.comnan
39204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_34a-0001.a-msedge.netTrue
40161.35.60.200North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
4135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
42157.245.84.7North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
4352.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-52-73-153-209.compute-1.amazonaws.comnan
44151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_33nanTrue
45157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
4613.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32nanTrue
4752.216.245.134AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4852.217.103.62AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
49167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
5052.217.69.158AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5152.217.75.174AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
52104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
5323.227.38.74OttawaOntarioAS13335 Cloudflare, Inc.K2PCanadatier_31nanTrue
5452.217.77.94AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5552.216.93.101AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5618.232.246.222AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-18-232-246-222.compute-1.amazonaws.comnan
5752.217.38.38AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5852.217.41.142AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5952.216.145.37AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website