Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
023523410512132021-04-21207.244.67.215Chrome
tierdomaincountregistrarname_serversorg
0tier_1onewhiteweb.com1Ripcurl Domains, LLCNS1.COMMONMX.COMNone
1tier_1namecoin-wallet.com1Domainnovations, LLCNS1.COMMONMX.COMNone
2tier_1antonaberg.info1DYNADOT LLCNS1.COMMONMX.COMNone
3tier_1my-movies.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1newmp4movies.in1Dynadot LLCns1.commonmx.comNone
5tier_1hisocraft.net1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159836646
6tier_1brawler.io1Dynadot, LLCNS1.COMMONMX.COMNone
7tier_1jallo.pro1DYNADOT LLCNS1.COMMONMX.COMNone
8tier_1endominicana.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1depedcebuprovince.ph1NoneNoneNone
10tier_21496.rawlexi.com184GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
11tier_2americanlisted.com175ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
12tier_29nl.es50NoneNoneNone
13tier_2newre-conversions.clickmeter.com50REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
14tier_2trk.jometer.com50Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
15tier_2api.l5srv.net50GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
16tier_2click.appcast.io26101Domain GRS LtdNS-85.AWSDNS-10.COMNone
17tier_2careerbliss.com16GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
18tier_2trk.careerbliss.com14GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
19tier_2click.appcast.io_LOOP_113NoneNoneNone
20tier_2rd.bizrate.com5MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
21tier_2click.expmediadirect.com4NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
22tier_2api.apptap.com4Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
23tier_2api.mplayit.com4Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
24tier_2redirect.viglink.com4Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
25tier_2link.sylikes.com4MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
26tier_2rd.connexity.net4NoneNoneNone
27tier_2jsv3.recruitics.com2TUCOWS, INC.NS-1237.AWSDNS-26.ORGREDACTED FOR PRIVACY
28tier_2cmp.jobs1NoneNS1.LINODE.COMNone
29tier_2aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGNone
30tier_3google.com99MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
31tier_3upward.careers50GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
32tier_3careerbliss.com10GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
33tier_3americanlisted.com9ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
34tier_3careerbuilder.com3CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
35tier_3linkedin.com3NoneNoneNone
36tier_3nextcareernow.com2GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
37tier_3trk.careerbliss.com2GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
38tier_3seattlejobs.com1NoneNoneNone
39tier_3memorialplan.nolig.com1GoDaddy.com, LLCNS1.DIGITALOCEAN.COMJob Post Media
40tier_3thredup.com1GoDaddy.com, LLCMATT.NS.CLOUDFLARE.COMThredUp Inc.
41tier_3wayfair.com1NoneNoneNone
42tier_3ballarddesigns.com_LOOP_21NoneNoneNone
43tier_3skechers.com1NoneNoneNone
44tier_3frontgate.com1Network Solutions, LLCNS1.HSN.NETNone
45tier_3rd.bizrate.com1NoneNoneNone
46tier_3feed.int.jobble.com1GoDaddy.com, LLCNS-1238.AWSDNS-26.ORGDomains By Proxy, LLC
47tier_3sanfranciscogigs.com1ENOM, INC.DNS1.NAME-SERVICES.COMREDACTED FOR PRIVACY
48tier_3jobs.bswhealth.com1Network Solutions, LLCNS03.BAYLORHEALTHCARE.COMNone
49tier_3savatree.com1GoDaddy.com, LLCAURORA.NS.CLOUDFLARE.COMSavATree
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_134nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_130nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
4206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
874.63.241.22DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1422-241-63-74.static.reverse.lstn.netnan
9185.107.56.197RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_2184nannan
1135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_39240.61.209.35.bc.googleusercontent.comnan
1267.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_250nannan
13207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_312cbsmtp1.careerbliss.comnan
1423.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_226ec2-23-21-53-13.compute-1.amazonaws.comnan
1523.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_225ec2-23-21-166-45.compute-1.amazonaws.comnan
1654.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_225ec2-54-197-247-190.compute-1.amazonaws.comnan
1754.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_224ec2-54-235-205-204.compute-1.amazonaws.comnan
1899.84.114.65NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_216server-99-84-114-65.ewr52.r.cloudfront.netnan
1999.84.114.25NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_216server-99-84-114-25.ewr52.r.cloudfront.netnan
20100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_31pool-100-37-135-2.nycmny.fios.verizon.netnan
2199.84.114.53NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_210server-99-84-114-53.ewr52.r.cloudfront.netnan
22100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-100-25-52-1.compute-1.amazonaws.comnan
233.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-3-234-0-165.compute-1.amazonaws.comnan
24192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31rd.bizrate.comnan
2599.84.114.17NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_28server-99-84-114-17.ewr52.r.cloudfront.netnan
2652.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-52-3-4-129.compute-1.amazonaws.comnan
2754.225.125.240AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-54-225-125-240.compute-1.amazonaws.comnan
28198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_24nannan
29192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_24rd.connexity.netnan
3067.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_350nannan
31172.217.7.4Clinton CornersNew YorkAS15169 Google LLC12514United Statestier_329lga25s56-in-f4.1e100.netnan
32172.217.10.100CliftonNew JerseyAS15169 Google LLC07015United Statestier_323lga34s15-in-f4.1e100.netnan
33142.250.64.68WestburyNew YorkAS15169 Google LLC11590United Statestier_316lga34s30-in-f4.1e100.netnan
34172.217.10.228CliftonNew JerseyAS15169 Google LLC07015United Statestier_315lga25s59-in-f4.1e100.netnan
35172.217.165.132Los AngelesCaliforniaAS15169 Google LLC90009United Statestier_315lax30s03-in-f4.1e100.netnan
36207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_312cbsmtp1.careerbliss.comnan
3735.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_39240.61.209.35.bc.googleusercontent.comnan
3813.107.42.14RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_33nanTrue
39216.239.32.21Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_32any-in-2015.1e100.netTrue
4068.168.84.129NorristownPennsylvaniaAS17378 TierPoint, LLC19403United Statestier_31129.84.168.68.static.dbsintl.netnan
41138.197.61.36CliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_31nannan
4299.84.47.93NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-47-93.ewr52.r.cloudfront.netnan
43104.18.22.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
4423.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-99.deploy.static.akamaitechnologies.comnan
45100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_31pool-100-37-135-2.nycmny.fios.verizon.netnan
46104.16.189.137San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
4799.84.47.14NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-47-14.ewr52.r.cloudfront.netnan
48142.250.80.4New York CityNew YorkAS15169 Google LLC10004United Statestier_31lga34s33-in-f4.1e100.netnan
49104.64.218.125New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31a104-64-218-125.deploy.static.akamaitechnologies.comnan
5099.84.47.36NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-47-36.ewr52.r.cloudfront.netnan
51192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31rd.bizrate.comnan
5254.234.245.31AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-234-245-31.compute-1.amazonaws.comnan
5368.168.84.133NorristownPennsylvaniaAS17378 TierPoint, LLC19403United Statestier_31133.84.168.68.static.dbsintl.netnan
5452.70.5.225AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-70-5-225.compute-1.amazonaws.comnan
55141.193.213.20AustinTexasAS209242 Cloudflare London, LLC78701United Statestier_31nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website