Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
07984274002020-10-19207.244.67.218Iphone
tierdomaincountregistrarname_serversorg
0tier_1kineticarsenal.net1Big House Services, LLCNS1.DNSNUTS.COMNone
1tier_1palyacoburada.net1EuropeanConnectionOnline.com LLCNS1.DNSNUTS.COMNone
2tier_1eazytrade.net1Domainsofvalue.com LLCNS1.DNSNUTS.COMNone
3tier_1fjyocojp.net1DropJump.com, LLCNS1.DNSNUTS.COMNone
4tier_1gwab.net1SNAPNAMES 84, LLCNS1.DNSNUTS.COMNone
5tier_1genuinagente.net1Name Find Source LLCNS1.DNSNUTS.COMNone
6tier_1miraner.net1Dropcatch Landing Spot LLCNS1.DNSNUTS.COMNone
7tier_1unlimited2.net1Draftpick Domains LLCNS1.DNSNUTS.COMNone
8tier_1gu-ru.net1Heavydomains.net LLCNS1.DNSNUTS.COMNone
9tier_1nutkau.net1Nom Infinitum, LLCNS1.DNSNUTS.COMNone
10tier_2changeslots.com34Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
11tier_2infopicked.com30NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
12tier_2track.tkbo.com21Key-Systems GmbHNS1.DNSRES.NETc/o whoisproxy.com
13tier_2p246485.infopicked.com15NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
14tier_2go.trackinz.com11NAMECHEAP INCNS-1139.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2click.expmediadirect.com10NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
16tier_2btpnative.com10GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
17tier_2p274639.infopicked.com9NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
18tier_2p185689.infopicked.com6NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
19tier_2usa.hermes-vib.com5Amazon Registrar, Inc.NS-1049.AWSDNS-03.ORGWhois Privacy Service
20tier_3theconnectvpn.com34DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
21tier_3clickherefun.com11NAMECHEAP INCNS-1036.AWSDNS-01.ORGWhoisGuard, Inc.
22tier_3allbestsecureus.com3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
23tier_3delightcmain.xyz2Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
24tier_3loveorfun.cc1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
25tier_3kinguin.net1GoDaddy.com, LLCJIM.NS.CLOUDFLARE.COMDomains By Proxy, LLC
ipcityregionpostalcountry_nametiercounthostname
0207.244.67.215ManassasVirginia20108United Statestier_111nan
1207.244.67.214ManassasVirginia20108United Statestier_19nan
2207.244.67.218ManassasVirginia20108United Statestier_19nan
337.48.65.150AmsterdamNorth Holland1012Netherlandstier_15nan
437.48.65.149AmsterdamNorth Holland1012Netherlandstier_14nan
5185.107.56.57RotterdamSouth Holland3012Netherlandstier_13nan
637.48.65.151AmsterdamNorth Holland1012Netherlandstier_12nan
7185.107.56.60RotterdamSouth Holland3012Netherlandstier_12nan
8185.107.56.58RotterdamSouth Holland3012Netherlandstier_12nan
9207.244.67.216ManassasVirginia20108United Statestier_12nan
10173.192.101.24DallasTexas75270United Statestier_26418.65.c0ad.ip4.static.sl-reverse.com
1134.207.32.33Virginia BeachVirginia23471United Statestier_234ec2-34-207-32-33.compute-1.amazonaws.com
12198.134.116.30New York CityNew York10013United Statestier_212nan
1334.226.252.28Virginia BeachVirginia23471United Statestier_211ec2-34-226-252-28.compute-1.amazonaws.com
14209.15.13.136TorontoOntarioM5NCanadatier_210nan
1594.130.186.231NürnbergBavaria90402Germanytier_27static.231.186.130.94.clients.your-server.de
1694.130.185.237NürnbergBavaria90402Germanytier_25static.237.185.130.94.clients.your-server.de
17138.201.252.161GeldernNorth Rhine-Westphalia47608Germanytier_24proxy.traffic.club
18144.76.0.242NürnbergBavaria90402Germanytier_23static.242.0.76.144.clients.your-server.de
1954.39.130.163LangfordBritish ColumbiaV9BCanadatier_33ns568503.ip-54-39-130.net
20104.27.187.165Atlantic CityNew Jersey08404United Statestier_315nan
21172.67.181.234New York CityNew York10004United Statestier_315nan
22144.202.92.101WashingtonVirginia22747United Statestier_311144.202.92.101.vultr.com
23104.27.186.165Atlantic CityNew Jersey08404United Statestier_34nan
2454.39.130.163LangfordBritish ColumbiaV9BCanadatier_33ns568503.ip-54-39-130.net
25216.239.38.21San JoseCalifornia95103United Statestier_31any-in-2615.1e100.net
26104.18.80.149New York CityNew York10004United Statestier_31nan
27104.18.78.149New York CityNew York10004United Statestier_31nan
28104.17.190.85New York CityNew York10004United Statestier_31nan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website