Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
024124612421102021-03-0537.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_1epayfaucets.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159169997
1tier_1erotop.info1DYNADOT LLCNS1.COMMONMX.COMNone
2tier_1biit.info1Dynadot, LLCNS1.COMMONMX.COMNone
3tier_1baicung.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1ginderfactory.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158845294
5tier_1gratgames.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159841841
6tier_13idi.me1GoDaddy.com, LLCNoneNone
7tier_1diziindir.org1Domainhysteria.com LLCNS1.COMMONMX.COMNone
8tier_1artdaily.me1Dynadot, LLCNoneNone
9tier_1conectarural.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2dprtb.com1151API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
11tier_2alfik-fik.com78Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
12tier_2nicanor-the.com54Amazon Registrar, Inc.NS-1242.AWSDNS-27.ORGWhois Privacy Service
13tier_2get.popplunder.com52NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_2trustedpush.com52NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2win1.trustedpush.com46NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
16tier_2ads35.adtelligent.com46DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
17tier_2dsp35.adtelligent.com46DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
18tier_2aibm1.mysearch.space46NoneNoneNone
19tier_2externals-1953518744.us-east-1.elb.amazonaws.com46MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
20tier_3bing.com45MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
21tier_3happymakesite.xyz22Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
22tier_3storystudio.sfgate.com21CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
23tier_3win3.trustedpush.com17NoneNoneNone
24tier_3win2.trustedpush.com16NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
25tier_3m.placesiteb.xyz13Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
26tier_3win4.trustedpush.com12NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
27tier_3win1.trustedpush.com6NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
28tier_3moneyfinancegold.com2NameCheap, Inc.ANNA.NS.CLOUDFLARE.COMNone
29tier_3get.popplunder.com2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_132nannan
1207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nannan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nannan
3207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_118nannan
4206.221.176.184WillingboroNew JerseyAS23470 ReliableSite.Net LLC08046United Statestier_118nannan
5104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
7185.107.56.197AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_14nannan
8104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_14nannan
974.63.241.24Los AngelesCaliforniaAS46475 Limestone Networks, Inc.90009United Statestier_1424-241-63-74.static.reverse.lstn.netnan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2118nannan
1134.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23458United Statestier_275ec2-34-200-146-95.compute-1.amazonaws.comnan
1213.225.230.12New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_39server-13-225-230-12.jfk51.r.cloudfront.netnan
1354.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23458United Statestier_258ec2-54-84-27-165.compute-1.amazonaws.comnan
1434.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23458United Statestier_252ec2-34-199-180-187.compute-1.amazonaws.comnan
15209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_246static-42-202-205-209.24shells.netnan
16209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_246static-43-202-205-209.24shells.netnan
1735.162.164.74PortlandOregonAS16509 Amazon.com, Inc.97256United Statestier_246ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
1813.225.230.115New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_236server-13-225-230-115.jfk51.r.cloudfront.netnan
19198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_232nannan
20204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_338a-0001.a-msedge.netTrue
21100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_333pool-100-37-135-2.nycmny.fios.verizon.netnan
2298.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_321nannan
23104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_319nanTrue
2413.225.230.12New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_39server-13-225-230-12.jfk51.r.cloudfront.netnan
25104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
2613.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_36nanTrue
27104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
2813.225.230.57New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_35server-13-225-230-57.jfk51.r.cloudfront.netnan
29104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website