Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02182341027002021-01-1237.48.65.149Chrome
tierdomaincountregistrarname_serversorg
0tier_19ref.com1Lionshare Domains, LLCNS1.DNSNUTS.COMThe Management Group II
1tier_1aharonic.net1Gradeadomainnames.com LLCNS1.DNSNUTS.COMNone
2tier_1deadchicksarecoolmodels.com1Communigal Communication LtdNS1.COMMONMX.COMNone
3tier_1buysellads.ph1NoneNoneNone
4tier_1fnanon.com1enom652, Inc.NS1.DNSNUTS.COMNone
5tier_1csfort.us1Communigal Communication Ltdns2.commonmx.comNone
6tier_1di1.us1Communigal Communication Ltdns2.commonmx.comNone
7tier_1bagustekno.net1Zone of Domains LLCNS1.DNSNUTS.COMNone
8tier_1flyingsg.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158841585
9tier_1cloudfilezz.com1Lionshare Domains, LLCNS1.DNSNUTS.COMThe Management Group II
10tier_2dprtb.com671API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
11tier_2alfik-fik.com58Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
12tier_2api.searchlinker.com52GoDaddy.com, LLCNS-1158.AWSDNS-16.ORGDomains By Proxy, LLC
13tier_2bestresults.xyz51NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_2my-search.com45Go China Domains, LLCNS-1080.AWSDNS-07.ORGDomains By Proxy, LLC
15tier_2bradamante-per.com43Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
16tier_2powerofsearches.com32GoDaddy.com, LLCDNS1.P09.NSONE.NETClientConnect LTD
17tier_2track.vcdc.com21Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
18tier_2forlumineontor.com20URL SOLUTIONS INC.NS-1239.AWSDNS-26.ORGGLOBAL DOMAIN PRIVACY SERVICES INC
19tier_2api.bestwebplayer.com20NAMECHEAP INCNS-1333.AWSDNS-38.ORGWhoisGuard, Inc.
20tier_3bing.com50MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
21tier_3get.streamssitesearch.com18GoDaddy.com, LLCISLA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
22tier_3searchfrequently.com10GoDaddy.com, LLCNEIL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
23tier_3gearbest.com7Alibaba Cloud Computing (Beijing) Co., Ltd.NS-1356.AWSDNS-41.ORGNone
24tier_3tjmzxqyhftsoptqvcnimforyraogdm.s3.amazonaws.com5MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
25tier_3yhesgyeblzntrmyyvtajhdgglamuqx.s3.amazonaws.com4MarkMonitor Inc.R1.AMAZONAWS.COMNone
26tier_3tgphrhcxzgrzhjjlfnnmgjntnetmol.s3.amazonaws.com4NoneNoneNone
27tier_3track.vcdc.com4Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
28tier_3sfolzqzvrkqnyvlseoojlpihvxacrj.s3.amazonaws.com4NoneNoneNone
29tier_3hmxlwfzjglqsupqvyccdeyfywsasht.s3.amazonaws.com3MarkMonitor Inc.R1.AMAZONAWS.COMNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nannan
1207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_119nannan
2207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_119nannan
3207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_113nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
6206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
737.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_16nannan
837.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
9104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_290nannan
11100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_263pool-100-37-135-2.nycmny.fios.verizon.netnan
1234.202.98.117Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_256ec2-34-202-98-117.compute-1.amazonaws.comnan
1334.226.113.11Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_245ec2-34-226-113-11.compute-1.amazonaws.comnan
143.213.168.177Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_227ec2-3-213-168-177.compute-1.amazonaws.comnan
1518.213.221.179Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_225ec2-18-213-221-179.compute-1.amazonaws.comnan
16178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_225nannan
1723.43.56.185New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_223a23-43-56-185.deploy.static.akamaitechnologies.comnan
1823.43.56.194New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_222a23-43-56-194.deploy.static.akamaitechnologies.comnan
1995.217.204.250HelsinkiUusimaaAS24940 Hetzner Online GmbH00100Finlandtier_218static.250.204.217.95.clients.your-server.denan
20204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_349a-0001.a-msedge.netTrue
21172.64.175.31San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_310nanTrue
22172.64.174.31San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_38nanTrue
23184.87.57.96New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_37a184-87-57-96.deploy.static.akamaitechnologies.comnan
24104.31.80.30San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
25172.67.138.156San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
26195.201.92.254NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_34static.254.92.201.195.clients.your-server.denan
27158.106.84.60TorontoOntarioAS23498 COGECODATAM5NCanadatier_33gay-hookup.comnan
28104.18.16.24San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
29139.45.196.79PoplarEnglandAS9002 RETN LimitedE14United Kingdomtier_32nannan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website