Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
016516863801272021-02-1837.48.65.149Safari
tierdomaincountregistrarname_serversorg
0tier_1hochkrimmel.de1NoneNoneNone
1tier_1arxivi.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
2tier_1cavallord.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159513995
3tier_1endominicana.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1ebookwarez.com1DYNADOT10 LLCNS1.COMMONMX.COMNone
5tier_1abcdwap.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1diziindir.org1Domainhysteria.com LLCNS1.COMMONMX.COMNone
7tier_1indianfreestuff.in1Dynadot LLCns1.commonmx.comNone
8tier_1dominiosinnova.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1flyingsg.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158841585
10tier_2dprtb.com761API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
11tier_2bradamante-per.com48Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
12tier_21496.wcitianka.com40GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
13tier_2americanlisted.com39ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
14tier_2click.appcast.io39101Domain GRS LtdNS-85.AWSDNS-10.COMNone
15tier_2btpnative.com191API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
16tier_2infopicked.com18NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
17tier_2managerformula.com18NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
18tier_2alfik-fik.com12Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
19tier_2joblift.com12INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMREDACTED FOR PRIVACY
20tier_3managerformula.com29NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
21tier_3careerbuilder.com25CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
22tier_3s3.amazonaws.com18MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
23tier_3affbank.com5DANESCO TRADING LTDGABE.NS.CLOUDFLARE.COMAdvertecy LTD
24tier_3crutchfield.com5Domain.com, LLCNS1.CRUTCHFIELD.COMREDACTED FOR PRIVACY
25tier_3nextcareernow.com4GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
26tier_3iosrecommendedvpn.com3NoneNoneNone
27tier_3jobleads.com3united domains AGCRUZ.NS.CLOUDFLARE.COMNone
28tier_3joblift.com2INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMREDACTED FOR PRIVACY
29tier_3bing.com2MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_121nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_117nannan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_116nannan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_110nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
6185.107.56.197AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_16nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
8185.107.56.199AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
9185.107.56.198AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_295nannan
11198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_240nannan
1235.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_239240.61.209.35.bc.googleusercontent.comnan
1354.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_230ec2-54-84-27-165.compute-1.amazonaws.comnan
1434.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_230ec2-34-200-146-95.compute-1.amazonaws.comnan
153.234.136.137Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_220ec2-3-234-136-137.compute-1.amazonaws.comnan
16173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21918.65.c0ad.ip4.static.sl-reverse.comnan
1752.0.220.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_219ec2-52-0-220-89.compute-1.amazonaws.comnan
18192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_212rd.bizrate.comnan
1935.190.64.22Kansas CityMissouriAS15169 Google LLC64121United Statestier_21222.64.190.35.bc.googleusercontent.comTrue
2023.43.56.211New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_39a23-43-56-211.deploy.static.akamaitechnologies.comnan
2123.43.56.200New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_38a23-43-56-200.deploy.static.akamaitechnologies.comnan
2213.224.211.40SeattleWashingtonAS16509 Amazon.com, Inc.98101United Statestier_38server-13-224-211-40.phl50.r.cloudfront.netnan
2313.224.211.117SeattleWashingtonAS16509 Amazon.com, Inc.98101United Statestier_37server-13-224-211-117.phl50.r.cloudfront.netnan
2413.224.211.92SeattleWashingtonAS16509 Amazon.com, Inc.98101United Statestier_36server-13-224-211-92.phl50.r.cloudfront.netnan
2535.156.139.229Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_35ec2-35-156-139-229.eu-central-1.compute.amazonaws.comnan
26205.196.12.74WashingtonWashington, D.C.AS54391 Crutchfield New Media LLC20045United Statestier_35www.crutchfield.comnan
27100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_35pool-100-37-135-2.nycmny.fios.verizon.netnan
2823.43.56.201New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_34a23-43-56-201.deploy.static.akamaitechnologies.comnan
2913.224.211.9SeattleWashingtonAS16509 Amazon.com, Inc.98101United Statestier_34server-13-224-211-9.phl50.r.cloudfront.netnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website