Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0150149570002020-12-22207.244.67.218Android
tierdomaincountregistrarname_serversorg
0tier_1omgmanga.com1GreenZoneDomains, LLCNS1.DNSNUTS.COMNone
1tier_1duet-chehova.net1Afterdark Domains, LLCNS1.DNSNUTS.COMNone
2tier_1ro-gaming.net1Tradewinds Names, LLCNS1.DNSNUTS.COMNone
3tier_1java-interview-questions.com1NamePal.com #8025, LLCNS1.DNSNUTS.COMNone
4tier_1kahimyang.info1Allearthdomains.com LLCNS1.DNSNUTS.COMThe Management Group II
5tier_1deskbg.com1SNAPNAMES 32, LLCNS1.DNSNUTS.COMNone
6tier_1sunshineconnections.org1Atomicdomainnames.com LLCNS1.DNSNUTS.COMThe Management Group II
7tier_1faidishare.com1SQUIDSAILERDOMAINS.COM, LLCNS1.DNSNUTS.COMNone
8tier_1torrentbuzz.net1Hang Ten Domains, LLCNS1.DNSNUTS.COMNone
9tier_1bryantan.info1BigLizarddomains.com LLCNS1.DNSNUTS.COMNone
10tier_2track.vcdc.com70Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
11tier_2euphe-gun.com53Amazon Registrar, Inc.NS-1325.AWSDNS-37.ORGWhois Privacy Service
12tier_2atnpx.com33GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2mnason-hec.com31Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
14tier_2get.popplunder.com31NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
15tier_2trustedpush.com29NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
16tier_2win1.trustedpush.com25NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
17tier_2win2.trustedpush.com21NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
18tier_2win3.trustedpush.com14NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
19tier_2dprtb.com10GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
20tier_3kbb.com27CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
21tier_3track.vcdc.com15Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
22tier_3win4.trustedpush.com8NameCheap, Inc.NS-1142.AWSDNS-14.ORGNone
23tier_3blog.sfgate.com8CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
24tier_3socalhondadealers.com7DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
25tier_3win3.trustedpush.com7NoneNoneNone
26tier_3robogarden.io6GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
27tier_3win1.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
28tier_3win2.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
29tier_3win5.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_121nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nannan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_119nannan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_119nannan
464.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_14customer.sharktech.netnan
537.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
6185.107.56.57AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
7185.107.56.58AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
837.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nannan
937.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nannan
1013.225.198.117MontréalQuebecAS16509 Amazon.com, Inc.H2WCanadatier_34server-13-225-198-117.yul62.r.cloudfront.netnan
1113.225.198.122MontréalQuebecAS16509 Amazon.com, Inc.H2WCanadatier_235server-13-225-198-122.yul62.r.cloudfront.netnan
1234.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_231ec2-34-199-180-187.compute-1.amazonaws.comnan
1334.202.98.117Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_226ec2-34-202-98-117.compute-1.amazonaws.comnan
1413.225.198.96MontréalQuebecAS16509 Amazon.com, Inc.H2WCanadatier_35server-13-225-198-96.yul62.r.cloudfront.netnan
1552.73.170.217Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_223ec2-52-73-170-217.compute-1.amazonaws.comnan
16104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_221nanTrue
1734.226.113.11Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_220ec2-34-226-113-11.compute-1.amazonaws.comnan
18144.76.0.242NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_218static.242.0.76.144.clients.your-server.denan
19144.76.1.130NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_218static.130.1.76.144.clients.your-server.denan
2023.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_327a23-44-217-143.deploy.static.akamaitechnologies.comnan
21100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_320pool-100-37-135-2.nycmny.fios.verizon.netnan
22195.201.92.254NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_315static.254.92.201.195.clients.your-server.denan
23151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_38nanTrue
2413.225.198.96MontréalQuebecAS16509 Amazon.com, Inc.H2WCanadatier_35server-13-225-198-96.yul62.r.cloudfront.netnan
2513.225.198.117MontréalQuebecAS16509 Amazon.com, Inc.H2WCanadatier_34server-13-225-198-117.yul62.r.cloudfront.netnan
26104.27.154.200San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
2734.207.4.240Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_34ec2-34-207-4-240.compute-1.amazonaws.comnan
2835.174.35.73Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_33ec2-35-174-35-73.compute-1.amazonaws.comnan
29172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website