Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
022022092301132021-01-3137.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_1bahargroup.asia1DYNADOT LLCNS1.COMMONMX.COMNone
1tier_1epfindian.in1Dynadot LLCns1.commonmx.comNone
2tier_1biit.info1DYNADOT LLCNS1.COMMONMX.COMNone
3tier_1arxivi.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1asibbsrcircle.in1Dynadot LLCns1.commonmx.comNone
5tier_1biyoukenkou.mobi1DYNADOT LLCNoneNone
6tier_1emonj.net1DYNADOT17 LLCNS1.COMMONMX.COMNone
7tier_19code.in1Dynadot LLCns1.commonmx.comNone
8tier_1dd-routers.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1dietplanforskolin.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_22893.wcitianka.com79GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
11tier_2cpakd.com78GoDaddy Online Services Cayman Islands LTDHUGH.NS.CLOUDFLARE.COMNone
12tier_2bradamante-per.com56Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
13tier_2get.popplunder.com56NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_2dprtb.com541API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
15tier_2trustedpush.com54NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
16tier_2win1.trustedpush.com44NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
17tier_2win2.trustedpush.com26NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
18tier_2click.expmediadirect.com15NoneNoneNone
19tier_2alfik-fik.com10Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
20tier_3b.joyspotmap.xyz38Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
21tier_3delightcmain.xyz36Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
22tier_3win3.trustedpush.com19NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
23tier_3win2.trustedpush.com18NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
24tier_3win1.trustedpush.com10NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
25tier_3win4.trustedpush.com7NameCheap, Inc.NS-1142.AWSDNS-14.ORGNone
26tier_3moneyfinancegold.com7NoneNoneNone
27tier_3search.yahoo.com5MarkMonitor, Inc.NS1.YAHOO.COMOath Inc.
28tier_3mergerinvesting.com4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
29tier_3rd.bizrate.com3MarkMonitor Inc.NS-1189.AWSDNS-20.ORGNone
ipcityregionorgpostalcountry_nametiercountanycasthostname
0207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_126nannan
1207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_124nannan
2207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nannan
3207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_117nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
7206.221.176.184HyattsvilleMarylandAS23470 ReliableSite.Net LLC20781United Statestier_110nannan
837.48.65.148SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_14nannan
9185.107.56.199AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_279nannan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_262nannan
12104.19.217.16San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_257Truenan
1334.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_256nanec2-34-199-180-187.compute-1.amazonaws.com
1434.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_243nanec2-34-200-146-95.compute-1.amazonaws.com
1513.225.218.113New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_39nanserver-13-225-218-113.jfk51.r.cloudfront.net
1613.225.218.47New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_36nanserver-13-225-218-47.jfk51.r.cloudfront.net
1713.225.218.85New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_230nanserver-13-225-218-85.jfk51.r.cloudfront.net
1854.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_224nanec2-54-84-27-165.compute-1.amazonaws.com
1913.225.218.79New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_223nanserver-13-225-218-79.jfk51.r.cloudfront.net
20100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_339nanpool-100-37-135-2.nycmny.fios.verizon.net
21104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_322Truenan
22104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_320Truenan
23104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313Truenan
24104.18.79.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313Truenan
25104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_310Truenan
2613.225.218.113New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_39nanserver-13-225-218-113.jfk51.r.cloudfront.net
2713.225.218.47New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_36nanserver-13-225-218-47.jfk51.r.cloudfront.net
2866.218.84.137Atlantic CityNew JerseyAS26101 Oath Holdings Inc.08404United Statestier_35nanats1.l7.search.vip.bf1.yahoo.com
2945.55.189.248CliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_34nannan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website