Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0156156438002020-11-21207.244.67.218Chrome
tierdomaincountregistrarname_serversorg
0tier_1emhdf.com1EastEndDomains, LLCNS1.DNSNUTS.COMNone
1tier_1theprettyladyblog.com1SNAPNAMES 40, LLCNS1.DNSNUTS.COMNone
2tier_1therebelscum.net1SNAPNAMES 27, LLCNS1.DNSNUTS.COMNone
3tier_1paladarhabana61.com1Compuglobalhypermega.com LLCNS1.DNSNUTS.COMNone
4tier_1pctclinic.com1Noteworthydomains, LLCNS1.DNSNUTS.COMNone
5tier_1sarkarsoft.com1Mypreciousdomain.com LLCNS1.DNSNUTS.COMNone
6tier_1bagustekno.net1Zone of Domains LLCNS1.DNSNUTS.COMNone
7tier_1teslersoftwareapp.com1Best Drop Names LLCNS1.DNSNUTS.COMNone
8tier_1chintaroh.com1SNAPNAMES 40, LLCNS1.DNSNUTS.COMNone
9tier_1jailbreaksiphones.com1SNAPNAMES 5, LLCNS1.DNSNUTS.COMNone
10tier_3protects.s3.us-east-2.amazonaws.com16MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
11tier_3bing.com14NoneNoneNone
12tier_3chrome.google.com11NoneNoneNone
13tier_3socalhondadealers.com6DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
14tier_3medianewpage.com4GoDaddy.com, LLCNS49.DOMAINCONTROL.COMDomains By Proxy, LLC
15tier_3turbo-pdf.com4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
16tier_3track.vcdc.com3Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
17tier_3wayfair.com2MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
18tier_3il.betrivers.com2GoDaddy.com, LLCERIN.NS.CLOUDFLARE.COMRivers IP Holdings, LLC
19tier_3funsafetab.com2GoDaddy.com, LLCNS69.DOMAINCONTROL.COMDomains By Proxy, LLC
20tier_2click.expmediadirect.com30NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
21tier_2sopho-kat.com28Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
22tier_2track.vcdc.com23Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
23tier_2pleasetrack.com16Name.com, Inc.NS1DJS.NAME.COMDomain Protection Services, Inc.
24tier_2stat1.info14GoDaddy.com, LLCNS15.DOMAINCONTROL.COMbingal media
25tier_2go.adesrc.com14Amazon Registrar, Inc.NS-1195.AWSDNS-21.ORGWhois Privacy Service
26tier_2fnd.adesrc.com14Amazon Registrar, Inc.NS-1195.AWSDNS-21.ORGWhois Privacy Service
27tier_2searchletter.com14GoDaddy.com, LLCDNS1.P09.NSONE.NETClientConnect LTD
28tier_24d3o4.rdtk.io11GoDaddy.com, LLCNS-239.AWSDNS-29.COMNone
29tier_2shiftexten.com11GoDaddy.com, LLCNS65.DOMAINCONTROL.COMDomains By Proxy, LLC
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_121nan
1207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_116nan
2207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_113nan
3207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_110nan
4185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nan
5185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nan
664.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_12customer.sharktech.net
7185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nan
837.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nan
937.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
10204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_311a-0001.a-msedge.net
11100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_37pool-100-37-135-2.nycmny.fios.verizon.net
12108.59.81.209Council BluffsIowaAS15169 Google LLC51502United Statestier_216209.81.59.108.bc.googleusercontent.com
1334.207.4.240Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_34ec2-34-207-4-240.compute-1.amazonaws.com
14178.128.246.195AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_34nan
15138.201.252.161GeldernNorth Rhine-WestphaliaAS24940 Hetzner Online GmbH47608Germanytier_33proxy.traffic.club
1613.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_33nan
17184.29.128.212EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_32a184-29-128-212.deploy.static.akamaitechnologies.com
18178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nan
19104.19.236.106San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nan
20198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_230nan
2123.81.176.198San FranciscoCaliforniaAS7203 Leaseweb USA, Inc.94103United Statestier_220nan
2252.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_218ec2-52-205-210-89.compute-1.amazonaws.com
2354.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_218ec2-54-225-132-253.compute-1.amazonaws.com
2434.230.167.153Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_216ec2-34-230-167-153.compute-1.amazonaws.com
25108.59.81.209Council BluffsIowaAS15169 Google LLC51502United Statestier_216209.81.59.108.bc.googleusercontent.com
2634.198.58.156Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_216ec2-34-198-58-156.compute-1.amazonaws.com
27132.148.19.88MesaArizonaAS26496 GoDaddy.com, LLC85214United Statestier_214ip-132-148-19-88.ip.secureserver.net
28184.72.70.186Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_212ec2-184-72-70-186.compute-1.amazonaws.com
2994.130.185.237NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_28static.237.185.130.94.clients.your-server.de

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website