Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0403794002020-10-05207.244.67.218Iphone
tierdomaincountregistrarname_serversorg
0tier_1filosofiaparaelexito.net1SNAPNAMES 91, LLCNS1.DNSNUTS.COMNone
1tier_1nentai.net1SNAPNAMES 75, LLCNS1.DNSNUTS.COMNone
2tier_11img.net1SNAPNAMES 78, LLCNS1.DNSNUTS.COMNone
3tier_1dualscene.net1EUTurbo.com LLCNS1.DNSNUTS.COMNone
4tier_1komikotaku.net1Octopusdomains.net LLCNS1.DNSNUTS.COMNone
5tier_1hmanga.net1Slow Putt Domains LLCNS1.DNSNUTS.COMNone
6tier_1smilealways.net1SNAPNAMES 26, LLCNS1.DNSNUTS.COMNone
7tier_1wwworf.at1EuroDNS SA ( https://nic.at/registrar/421 )Nonecompany
8tier_1marxio-tools.net1SNAPNAMES 36, LLCNS1.DNSNUTS.COMNone
9tier_1stcc.net1OldWorldAliases.com LLCNS1.DNSNUTS.COMNone
10tier_2click.expmediadirect.com11NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
11tier_2btpnative.com7GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
12tier_2infopicked.com6NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
13tier_2p274639.infopicked.com6NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
14tier_2changeslots.com5Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
15tier_2myfirsttab.com5GoDaddy.com, LLCNS1.LINODE.COMDomains By Proxy, LLC
16tier_2search.eproute.info5GoDaddy.com, LLCNS22.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2rockymountaintrack.com5Registrar of domain names REG.RU LLCNS1.REG.RUPrivate Person
18tier_2qvikar.com1Sea Wasp, LLCNS2789.HOSTGATOR.COMSavvy Investments, LLC Privacy ID# 1016679
19tier_2clkmg.com1GoDaddy.com, LLCNS1.SOFTLAYER.COMClickMagick, Inc.
20tier_3theconnectvpn.com5DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
21tier_3everydayconsumers.com5GoDaddy.com, LLCJANET.NS.CLOUDFLARE.COMDomains By Proxy, LLC
22tier_3vpnhub.com5Eurodns S.A.DNS1.P03.NSONE.NETWhois Privacy (enumDNS dba)
23tier_3vitacosg.com1Key-Systems GmbHNS1.BODIS.COMc/o whoisproxy.com
24tier_3allbestsecureus.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
25tier_3myhugesavings.com1Amazon Registrar, Inc.NS-1358.AWSDNS-41.ORGWhois Privacy Service
26tier_3ww1.survey-smiles.com1Internet Domain Service BS Corp.NS1.HASTYDNS.COMWhois Privacy Corp.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_16nan
1207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_13nan
2207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_13nan
3207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_12nan
464.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_11customer.sharktech.net
537.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
646.166.182.113AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
746.166.182.116AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
846.166.182.110AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
9173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21318.65.c0ad.ip4.static.sl-reverse.com
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_211nan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_27nan
1234.226.252.28Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_25ec2-34-226-252-28.compute-1.amazonaws.com
13172.104.144.44Frankfurt am MainHesseAS63949 Linode, LLC60311Germanytier_25li1660-44.members.linode.com
14167.114.103.223TorontoOntarioAS16276 OVH SASM5NCanadatier_25ns511363.ip-167-114-103.net
1534.223.196.33PortlandOregonAS16509 Amazon.com, Inc.97220United Statestier_23ec2-34-223-196-33.us-west-2.compute.amazonaws.com
1634.223.115.56PortlandOregonAS16509 Amazon.com, Inc.97220United Statestier_22ec2-34-223-115-56.us-west-2.compute.amazonaws.com
17192.254.234.214HoustonTexasAS46606 Unified Layer77092United Statestier_21192-254-234-214.unifiedlayer.com
1850.97.244.203San JoseCaliforniaAS36351 SoftLayer Technologies Inc.95103United Statestier_21clkmg.com
1966.254.114.123Los AngelesCaliforniaAS29789 Reflected Networks, Inc.90009United Statestier_35reflectededge.reflected.net
20104.27.186.165Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_33nan
21104.27.187.165Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_32nan
22104.24.118.18Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_32nan
23104.24.119.18Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_32nan
24172.67.219.253New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_31nan
25199.59.242.153TampaFloridaAS395082 Bodis, LLC33609United Statestier_31nan
2654.39.130.163LangfordBritish ColumbiaAS16276 OVH SASV9BCanadatier_31ns568503.ip-54-39-130.net
2718.237.90.114PortlandOregonAS16509 Amazon.com, Inc.97220United Statestier_31ec2-18-237-90-114.us-west-2.compute.amazonaws.com
28208.91.196.145AustinTexasAS19905 NeuStar, Inc.78701United Statestier_31nan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website