Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
025725810811482021-02-1937.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_13waycafe.com1DYNADOT LLCNS1.COMMONMX.COMNone
1tier_1andover.me1Dynadot, LLCNoneNone
2tier_1a-r-d.me1Dynadot, LLCNoneNone
3tier_1filmapik.tv1Domain Landing Zone LLCNS1.COMMONMX.COMNone
4tier_180089999.me1Dynadot, LLCNoneNone
5tier_1bajargratismp3.me1GoDaddy.com, LLCNoneNone
6tier_1amouretsante.co1Communigal Communication Ltdns1.commonmx.comNone
7tier_1bbpress.me1Dynadot, LLCNoneNone
8tier_1diverte.me1Dynadot, LLCNoneNone
9tier_1bexindonesia.com1Domaintimemachine.com LLCNS1.COMMONMX.COMNone
10tier_2dprtb.com741API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
11tier_22893.wcitianka.com68GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
12tier_2awakeningsco.com68GoDaddy Online Services Cayman Islands LTDHUGH.NS.CLOUDFLARE.COMNone
13tier_2bradamante-per.com64Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
14tier_2get.popplunder.com64NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
15tier_2trustedpush.com64NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
16tier_2win1.trustedpush.com52NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
17tier_2alfik-fik.com30Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
18tier_2win2.trustedpush.com25NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
19tier_262252.click.validclick.net14Safenames LtdNS1.FULLMAILBOX.COMNone
20tier_3win2.trustedpush.com27NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
21tier_3happymakesite.xyz26Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
22tier_3m.placesiteb.xyz22Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
23tier_3win3.trustedpush.com18NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
24tier_3storystudio.sfgate.com14CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
25tier_3win1.trustedpush.com12NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
26tier_3b.delightcmain.xyz9Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
27tier_3bing.com8MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
28tier_3win4.trustedpush.com7NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
29tier_3b.funmapd.xyz6Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_131nannan
1207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_128nannan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nannan
3207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nannan
4206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_117nannan
5104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
8185.107.56.199AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_14nannan
9185.107.56.200AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_286nannan
11198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_268nannan
1234.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_264ec2-34-199-180-187.compute-1.amazonaws.comnan
1354.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_252ec2-54-84-27-165.compute-1.amazonaws.comnan
1413.225.62.25NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_317server-13-225-62-25.ewr53.r.cloudfront.netnan
1534.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_242ec2-34-200-146-95.compute-1.amazonaws.comnan
16104.18.2.198San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_238nanTrue
1713.225.62.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_236server-13-225-62-107.ewr53.r.cloudfront.netnan
1813.225.62.7NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_231server-13-225-62-7.ewr53.r.cloudfront.netnan
19104.18.3.198San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_230nanTrue
20100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_334pool-100-37-135-2.nycmny.fios.verizon.netnan
21104.18.79.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_323nanTrue
2213.225.62.25NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_317server-13-225-62-25.ewr53.r.cloudfront.netnan
23104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_316nanTrue
24104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_316nanTrue
25104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314nanTrue
2698.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_314nannan
27104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_38nanTrue
28204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_38a-0001.a-msedge.netTrue
2913.225.62.54NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_36server-13-225-62-54.ewr53.r.cloudfront.netnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website