Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0169177586002020-11-29207.244.67.218Iphone
tierdomaincountregistrarname_serversorg
0tier_1acg92.com1Allworldnames.com LLCNS1.DNSNUTS.COMNone
1tier_1awesomwallpaper.com1SNAPNAMES 22, LLCNS1.DNSNUTS.COMNone
2tier_1apps-security22.com1Domainsinthebag.com LLCNS1.DNSNUTS.COMNone
3tier_1accastiboat.com1Domainplace LLCNS1.DNSNUTS.COMNone
4tier_168psd.com1Treasure Trove Domains LLCNS1.DNSNUTS.COMNone
5tier_1bklynbeautymix.com1Namecatch Zone LLCNS1.DNSNUTS.COMNone
6tier_1bamsora1.com1Namesource LLCNS1.DNSNUTS.COMNone
7tier_121nl.com1Wide Right Domains LLCNS1.DNSNUTS.COMNone
8tier_122ndcompany.com1Bonam Fortunam Domains, LLCNS1.DNSNUTS.COMNone
9tier_1bandarkota.com1Ripcurl Domains, LLCNS1.DNSNUTS.COMNone
10tier_3theconnectvpn.com45DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
11tier_3checkthistime.com28NAMECHEAP INCNS-1262.AWSDNS-29.ORGWhoisGuard, Inc.
12tier_3track.vcdc.com15Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
13tier_3socalhondadealers.com7NoneNoneNone
14tier_3blog.chron.com5CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Newspapers, LLC
15tier_3blog.sfgate.com5CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
16tier_3music.apple.com3CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
17tier_3allbestsecureus.com2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
18tier_3sopho-kat.com1Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
19tier_360645.click.validclick.net1Safenames LtdNS1.FULLMAILBOX.COMNone
20tier_2infopicked.com47NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
21tier_2changeslots.com45Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
22tier_2track.vcdc.com44Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
23tier_2sopho-kat.com35Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
24tier_2go.trackinz.com28NAMECHEAP INCNS-1139.AWSDNS-14.ORGWhoisGuard, Inc.
25tier_2api.quotes.com24Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
26tier_2btpnative.com18GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
27tier_2p274639.infopicked.com17NoneNoneNone
28tier_2p54677.infopicked.com16NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
29tier_2p246485.infopicked.com14NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_137nan
1207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nan
3207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nan
464.32.8.67Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_14customer.sharktech.net
537.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nan
6185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nan
764.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_12customer.sharktech.net
864.32.8.68Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_12customer.sharktech.net
937.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nan
10138.68.8.221Santa ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_328nan
11104.27.186.165San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_322nan
12138.201.252.161GeldernNorth Rhine-WestphaliaAS24940 Hetzner Online GmbH47608Germanytier_315proxy.traffic.club
13104.27.187.165San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314nan
14151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_310nan
15172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_39nan
1635.174.35.73AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34ec2-35-174-35-73.compute-1.amazonaws.com
17100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_33pool-100-37-135-2.nycmny.fios.verizon.net
1834.207.4.240AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-34-207-4-240.compute-1.amazonaws.com
1954.39.130.163MontréalQuebecAS16276 OVH SASH3ACanadatier_32ns568503.ip-54-39-130.net
20173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_29618.65.c0ad.ip4.static.sl-reverse.com
2134.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_245ec2-34-207-32-33.compute-1.amazonaws.com
2234.226.252.28AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_228ec2-34-226-252-28.compute-1.amazonaws.com
235.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_224nan
24209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_223nan
2552.205.210.89AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-52-205-210-89.compute-1.amazonaws.com
2694.130.185.237NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_214static.237.185.130.94.clients.your-server.de
2754.225.132.253AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_214ec2-54-225-132-253.compute-1.amazonaws.com
28144.76.1.130NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_212static.130.1.76.144.clients.your-server.de
29204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_210204.44.79.214.static.quadranet.com

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website