Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
07467152002020-10-0837.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_1beritatrendz.com1Nameselite, LLCNS1.DNSNUTS.COMNone
1tier_1geek-republic.com1Treasure Trove Domains LLCNS1.DNSNUTS.COMThe Management Group II
2tier_1wahanaponsel.com1Heavydomains.net LLCNS1.DNSNUTS.COMThe Management Group II
3tier_1night-support24.com1eNom399, IncorporatedNS1.DNSNUTS.COMNone
4tier_1beagle-voyage.com1Aquarius Domains, LLCNS1.DNSNUTS.COMNone
5tier_1dqmj3.net1Domainsofcourse.com LLCNS1.DNSNUTS.COMThe Management Group II
6tier_1mjnexpress.com1SearchNResQ Inc.NS1.DNSNUTS.COMThe Management Group II
7tier_1rucinema.net1Sliceofheaven Domains, LLCNS1.DNSNUTS.COMThe Management Group II
8tier_1outaroad.com1Sssasss, IncorporatedNS1.DNSNUTS.COMThe Management Group II
9tier_1rg-mechanics-games.com1NamePal.com #8028 Inc.NS1.DNSNUTS.COMThe Management Group II
10tier_2dprtb.com6GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
11tier_2get.popplunder.com6NoneNoneNone
12tier_2trustedpush.com6NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
13tier_2win1.trustedpush.com6NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
14tier_2win2.trustedpush.com6NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2trackyourmpg.com6UNIREGISTRAR CORPHUGH.NS.CLOUDFLARE.COMNone
16tier_2win3.trustedpush.com5NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
17tier_2c.trafficslide.org5GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
18tier_211168258.searchiqnet.com5GoDaddy.com, LLCNS57.DOMAINCONTROL.COMDomains By Proxy, LLC
19tier_2convertpdfpro.com4GoDaddy.com, LLCNINA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
20tier_3win4.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
21tier_3us.search.yahoo.com4MarkMonitor, Inc.NS1.YAHOO.COMOath Inc.
22tier_3gladmpath.xyz3Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
23tier_3delightcmain.xyz3Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
24tier_3win6.trustedpush.com1NoneNoneNone
25tier_3b.gladspotwonder.xyz1Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
26tier_3win3.trustedpush.com1NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
27tier_3bodybuilding.com1MarkMonitor, Inc.NS1.BODYBUILDING.COMBodybuilding.com
28tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETMacy's Systems and Technology, Inc.
29tier_3b.meeryslotspin.xyz1Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_17nan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_17nan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_16nan
3207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_15nan
4209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_214nan
599.84.118.101NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-118-101.ewr52.r.cloudfront.net
699.84.118.87NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-118-87.ewr52.r.cloudfront.net
752.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_28ec2-52-205-210-89.compute-1.amazonaws.com
8209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_27nan
934.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_26ec2-34-199-180-187.compute-1.amazonaws.com
10199.59.242.153TampaFloridaAS395082 Bodis, LLC33609United Statestier_25nan
11104.18.25.3Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_25nan
1266.218.84.137Atlantic CityNew JerseyAS26101 Oath Holdings Inc.08404United Statestier_34ats1.l7.search.vip.bf1.yahoo.com
1354.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_24ec2-54-225-132-253.compute-1.amazonaws.com
1466.218.84.137Atlantic CityNew JerseyAS26101 Oath Holdings Inc.08404United Statestier_34ats1.l7.search.vip.bf1.yahoo.com
15104.18.81.149Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_34nan
16104.18.82.149Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_33nan
1799.84.118.101NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-118-101.ewr52.r.cloudfront.net
1899.84.118.87NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-118-87.ewr52.r.cloudfront.net
19104.18.80.149Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_32nan
20184.85.2.167Atlantic CityNew JerseyAS16625 Akamai Technologies, Inc.08404United Statestier_31a184-85-2-167.deploy.static.akamaitechnologies.com
21104.18.79.149Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_31nan
2299.84.118.103NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-118-103.ewr52.r.cloudfront.net
23104.77.220.218NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a104-77-220-218.deploy.static.akamaitechnologies.com

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website