Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
08482182002020-10-19207.244.67.218Chrome
tierdomaincountregistrarname_serversorg
0tier_1kineticarsenal.net1Big House Services, LLCNS1.DNSNUTS.COMNone
1tier_1miraner.net1Dropcatch Landing Spot LLCNS1.DNSNUTS.COMNone
2tier_1wowo.net1Alibaba Cloud Computing (Beijing) Co., Ltd.NS1.DNSNUTS.COMNone
3tier_1zonamovie.net1Extra Threads, LLCNS1.DNSNUTS.COMNone
4tier_1nutkau.net1Nom Infinitum, LLCNS1.DNSNUTS.COMNone
5tier_1america-ferrera.net1Name Connection Area LLCNS1.DNSNUTS.COMNone
6tier_1crazyleaks.net1SNAPNAMES 52, LLCNS1.DNSNUTS.COMNone
7tier_1fluttercn.net1DropExtra.com, LLCNS1.DNSNUTS.COMNone
8tier_1konayuki.net1Namesource LLCNS1.DNSNUTS.COMNone
9tier_1onoffswitch.net1Touchdown Domains LLCNS1.DNSNUTS.COMNone
10tier_2dprtb.com14GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
11tier_21496.wcitianka.com14UNIREGISTRAR CORPNS-1096.AWSDNS-09.ORGNone
12tier_2btpnative.com7GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
13tier_2infopicked.com7NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
14tier_2p274639.infopicked.com7NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
15tier_2106.trackints.com7NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
16tier_2usa.mnason-hec.com5Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
17tier_2americanlisted.com5ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
18tier_2click.appcast.io5101domain GRS LtdNS-85.AWSDNS-10.COMNone
19tier_2toovolution.club4NAMECHEAP INCdemi.ns.cloudflare.comWhoisGuard, Inc.
20tier_3americanlisted.com9ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
21tier_3pestexterminator.com7GoDaddy.com, LLCNS-1521.AWSDNS-62.ORGDomains By Proxy, LLC
22tier_3smartdeals.icu3NAMECHEAP INCNS-813.AWSDNS-37.NETWhoisGuard, Inc.
23tier_3toovolution.club2NAMECHEAP INCdemi.ns.cloudflare.comWhoisGuard, Inc.
24tier_3shipt.com_LOOP_12NoneNoneNone
25tier_3w20nb.wolve.pro1DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
26tier_37ko0m.wolve.pro1DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
27tier_3us.allthetopbananas.com1ENOM, INC.DANE.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
28tier_3a6xs0.wolve.pro1DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
29tier_3ewm3x.wolve.pro1DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
ipcityregionpostalcountry_nametiercounthostname
0207.244.67.218ManassasVirginia20108United Statestier_110nan
1207.244.67.214ManassasVirginia20108United Statestier_17nan
2207.244.67.215ManassasVirginia20108United Statestier_16nan
3207.244.67.216ManassasVirginia20108United Statestier_15nan
437.48.65.150AmsterdamNorth Holland1012Netherlandstier_11nan
5185.107.56.58RotterdamSouth Holland3012Netherlandstier_11nan
637.48.65.148AmsterdamNorth Holland1012Netherlandstier_11nan
737.48.65.149AmsterdamNorth Holland1012Netherlandstier_11nan
8209.15.13.136TorontoOntarioM5NCanadatier_221nan
9198.54.112.216San JoseCalifornia95103United Statestier_217nan
10173.192.101.24DallasTexas75270United Statestier_21418.65.c0ad.ip4.static.sl-reverse.com
11108.168.193.185DallasTexas75270United Statestier_27b9.c1.a86c.ip4.static.sl-reverse.com
1252.205.210.89Virginia BeachVirginia23471United Statestier_25ec2-52-205-210-89.compute-1.amazonaws.com
1335.209.61.240ChicagoIllinois60666United Statestier_39240.61.209.35.bc.googleusercontent.com
14207.38.44.116IrvineCalifornia92618United Statestier_31cbsmtp1.careerbliss.com
15100.37.135.2New York CityNew York10004United Statestier_37pool-100-37-135-2.nycmny.fios.verizon.net
16176.9.117.45AltusriedBavaria87452Germanytier_23static.45.117.9.176.clients.your-server.de
1754.163.21.106Virginia BeachVirginia23471United Statestier_23ec2-54-163-21-106.compute-1.amazonaws.com
1835.209.61.240ChicagoIllinois60666United Statestier_39240.61.209.35.bc.googleusercontent.com
19100.37.135.2New York CityNew York10004United Statestier_37pool-100-37-135-2.nycmny.fios.verizon.net
20204.13.108.145RichardsonTexas75082United Statestier_37nan
2194.102.49.124AmsterdamNorth Holland1012Netherlandstier_33no-reverse-dns-configured.com
2299.84.221.49WashingtonWashington, D.C.20045United Statestier_31server-99-84-221-49.iad79.r.cloudfront.net
23172.67.75.236New York CityNew York10004United Statestier_31nan
2499.84.221.10WashingtonWashington, D.C.20045United Statestier_31server-99-84-221-10.iad79.r.cloudfront.net
25104.17.190.85New York CityNew York10004United Statestier_31nan
26104.19.183.41Atlantic CityNew Jersey08404United Statestier_31nan
27207.38.44.116IrvineCalifornia92618United Statestier_31cbsmtp1.careerbliss.com

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website