Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0195207757002020-12-1537.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_1avg4.us1UdomainName.com LLCns1.dnsnuts.comNone
1tier_1playrusthq.com1Bounce Pass Domains LLCNS1.DNSNUTS.COMThe Management Group II
2tier_1mysocaledlife.com1Magnolia Domains, LLCNS1.DNSNUTS.COMNone
3tier_1templatesuplex.com1Skykomishdomains.com LLCNS1.DNSNUTS.COMNone
4tier_1somedecor.com1Biglizarddomains.com LLCNS1.DNSNUTS.COMNone
5tier_1garciniacambogiasideeffects4u.com1Rally Cry Domains, LLCNS1.DNSNUTS.COMNone
6tier_1ausujet.com1Domain Name Root, LLCNS1.DNSNUTS.COMThe Management Group II
7tier_1dakmm.com1Private Domains, IncorporatedNS1.DNSNUTS.COMNone
8tier_1banalitech.com1DropWeek.com, Inc.NS1.DNSNUTS.COMNone
9tier_1poisonx.us1UdomainName.com LLCns2.dnsnuts.comNone
10tier_2track.vcdc.com76Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
11tier_2euphe-gun.com62Amazon Registrar, Inc.NS-1325.AWSDNS-37.ORGWhois Privacy Service
12tier_2mnason-hec.com41Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
13tier_2get.popplunder.com41NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_2trustedpush.com39NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2win1.trustedpush.com35NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
16tier_2win2.trustedpush.com32NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
17tier_2atnpx.com27GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
18tier_2ad.doubleclick.net25MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
19tier_2win3.trustedpush.com21NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
20tier_3kbb.com24CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
21tier_3track.vcdc.com17Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
22tier_3win4.trustedpush.com13NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
23tier_3win3.trustedpush.com11NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
24tier_3blog.sfgate.com11CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
25tier_3blog.chron.com11CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Newspapers, LLC
26tier_3win5.trustedpush.com7NameCheap, Inc.NS-1142.AWSDNS-14.ORGNone
27tier_3wayfair.com4MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
28tier_3win1.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
29tier_3blog.mysanantonio.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMThe Hearst Corporation
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_134nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_124nannan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nannan
3207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nannan
437.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_16nannan
537.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nannan
6185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
764.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_12customer.sharktech.netnan
837.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nannan
9185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nannan
1013.225.229.73New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_37server-13-225-229-73.jfk51.r.cloudfront.netnan
1134.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_241ec2-34-199-180-187.compute-1.amazonaws.comnan
123.221.180.161Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_240ec2-3-221-180-161.compute-1.amazonaws.comnan
13204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_227204.44.79.214.static.quadranet.comnan
1452.73.170.217Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_222ec2-52-73-170-217.compute-1.amazonaws.comnan
15144.76.1.130NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_222static.130.1.76.144.clients.your-server.denan
1634.202.98.117Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_222ec2-34-202-98-117.compute-1.amazonaws.comnan
1734.226.113.11Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_219ec2-34-226-113-11.compute-1.amazonaws.comnan
1894.130.186.231NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_219static.231.186.130.94.clients.your-server.denan
19172.217.10.6Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_219lga34s12-in-f6.1e100.netnan
20151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_327nanTrue
21100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_326pool-100-37-135-2.nycmny.fios.verizon.netnan
22195.201.92.254NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_315static.254.92.201.195.clients.your-server.denan
2323.66.194.233New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_310a23-66-194-233.deploy.static.akamaitechnologies.comnan
2423.33.130.92New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_38a23-33-130-92.deploy.static.akamaitechnologies.comnan
2513.225.229.73New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_37server-13-225-229-73.jfk51.r.cloudfront.netnan
26104.105.89.43New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_36a104-105-89-43.deploy.static.akamaitechnologies.comnan
2713.225.190.56MontréalQuebecAS16509 Amazon.com, Inc.H2WCanadatier_32server-13-225-190-56.yul62.r.cloudfront.netnan
2823.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-41-189-99.deploy.static.akamaitechnologies.comnan
29144.76.0.242NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_32static.242.0.76.144.clients.your-server.denan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website