Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01261234240452021-01-1737.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_1alriyadh.us1Communigal Communication Ltdns2.commonmx.comNone
1tier_1cdhatver.com1NamePal.com #8010, LLCNS1.COMMONMX.COMNone
2tier_12homeremedies.com1NoneNoneNone
3tier_14779.info1DYNADOT LLCNS1.COMMONMX.COMNone
4tier_1bigcleandetailing.com1NoneNoneNone
5tier_1333tk.net1Annapurna Domains LLCNS1.COMMONMX.COMNone
6tier_1123kingcash.com1YouDamain.com LLCNS1.DNSNUTS.COMNone
7tier_1bookglobal.net1SNAPNAMES 9, LLCNS1.COMMONMX.COMNone
8tier_1beastfriend.in1Dynadot LLCns1.commonmx.comNone
9tier_1casl.info1DYNADOT LLCNS1.COMMONMX.COMNone
10tier_2bradamante-per.com25Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
11tier_2get.popplunder.com25NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
12tier_2trustedpush.com24NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
13tier_2win1.trustedpush.com24NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
14tier_2win2.trustedpush.com23NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2dprtb.com211API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
16tier_21496.wcitianka.com15GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
17tier_2americanlisted.com14ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
18tier_2rd.nebulajobs.com14NoneNoneNone
19tier_2win3.trustedpush.com14NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
20tier_3win3.trustedpush.com9NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
21tier_3win4.trustedpush.com8NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
22tier_3signup.finddreamjobs.com5GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
23tier_3agatrck.com5Amazon Registrar, Inc.NS-1518.AWSDNS-61.ORGWhois Privacy Service
24tier_3win5.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
25tier_3godaddy.com3GoDaddy.com, LLCA1-245.AKAM.NETGo Daddy Operating Company, LLC
26tier_3delightcmain.xyz3Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
27tier_3click.appcast.io_LOOP_13NoneNoneNone
28tier_3toprevenuecpmnetwork.com2NoneNoneNone
29tier_3b.jubilantdstreet.xyz2Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_110nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_19nannan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_19nannan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_18nannan
4206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_14nannan
8185.107.56.198AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_12nannan
9185.107.56.59AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nannan
1013.225.229.113New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_229server-13-225-229-113.jfk51.r.cloudfront.netnan
1113.225.229.12New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-229-12.jfk51.r.cloudfront.netnan
1234.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_226ec2-34-199-180-187.compute-1.amazonaws.comnan
13209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_224nannan
1413.225.229.73New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-229-73.jfk51.r.cloudfront.netnan
15198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_217nannan
1634.202.98.117Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_215ec2-34-202-98-117.compute-1.amazonaws.comnan
1713.225.229.61New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_35server-13-225-229-61.jfk51.r.cloudfront.netnan
1835.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_214240.61.209.35.bc.googleusercontent.comnan
1934.226.113.11Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_212ec2-34-226-113-11.compute-1.amazonaws.comnan
20100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_319pool-100-37-135-2.nycmny.fios.verizon.netnan
2113.225.229.61New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_35server-13-225-229-61.jfk51.r.cloudfront.netnan
22104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
2354.205.191.137Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_35ec2-54-205-191-137.compute-1.amazonaws.comnan
24184.87.68.204NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a184-87-68-204.deploy.static.akamaitechnologies.comnan
25104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
2613.225.229.73New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-229-73.jfk51.r.cloudfront.netnan
273.211.178.164Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_32ec2-3-211-178-164.compute-1.amazonaws.comnan
2813.225.229.12New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-229-12.jfk51.r.cloudfront.netnan
2952.200.114.82Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_31ec2-52-200-114-82.compute-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website