Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
022623013510962021-03-2237.48.65.149Chrome
tierdomaincountregistrarname_serversorg
0tier_1yellownovels.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
1tier_1etheldredasplace.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
2tier_1aurbataao.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159179997
3tier_1morebest.net1Register.com, Inc.NS1.COMMONMX.COMNone
4tier_1kadraya.net1Fastball Domains LLCNS1.COMMONMX.COMNone
5tier_1redmarka.net1Shining Star Domains, LLCNS1.COMMONMX.COMNone
6tier_1javweb.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1gzqsl.net1Freshbreweddomains.com LLCNS1.COMMONMX.COMNone
8tier_1emonj.net1DYNADOT17 LLCNS1.COMMONMX.COMNone
9tier_1smmarket.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2btpnav.com1531API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aglai-tan.com118Amazon Registrar, Inc.NS-1083.AWSDNS-07.ORGWhois Privacy Service
12tier_2ads35.adtelligent.com69DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
13tier_2dsp35.adtelligent.com69DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
14tier_2aldb1.mysearch.space69NoneNoneNone
15tier_2externals-1953518744.us-east-1.elb.amazonaws.com68MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
16tier_2search.snjsearch.com68GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2americanlisted.com41ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
18tier_21496.wcitianka.com36GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
19tier_2seekallanswrs.com31NameSilo, LLCNS-CLOUD-A1.GOOGLEDOMAINS.COMSee PrivacyGuardian.org
20tier_3bing.com49MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
21tier_3irl.com47GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
22tier_3google.com41NoneNoneNone
23tier_3search.yahoo.com18NoneNoneNone
24tier_3aliexpress.com_LOOP_16NoneNoneNone
25tier_3reebok.com3CSC CORPORATE DOMAINS, INC.NS1.NETNAMES.NETReebok International, Ltd.
26tier_3squirt.org2NAMECHEAP INCNS5.DNSMADEEASY.COMWhoisGuard, Inc.
27tier_3rd.bizrate.com1MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
28tier_32.dailymedia.cyou1NoneNoneNone
29tier_3reebok.com_LOOP_11NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_131nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_125nannan
2207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_123nannan
3207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_121nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
737.48.65.148SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_15nannan
8185.107.56.200RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
9104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2157nannan
11209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_269static-42-202-205-209.24shells.netnan
12209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_269static-43-202-205-209.24shells.netnan
1335.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_268ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
1454.84.27.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_266ec2-54-84-27-165.compute-1.amazonaws.comnan
1534.200.146.95AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_257ec2-34-200-146-95.compute-1.amazonaws.comnan
1635.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_241240.61.209.35.bc.googleusercontent.comnan
1750.16.173.246AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_237ec2-50-16-173-246.compute-1.amazonaws.comnan
183.125.109.211Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_237ec2-3-125-109-211.eu-central-1.compute.amazonaws.comnan
19198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_236nannan
20204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_346nanTrue
2166.218.84.137Atlantic CityNew JerseyAS26101 Oath Holdings Inc.08404United Statestier_318ats1.l7.search.vip.bf1.yahoo.comnan
22172.217.12.132CliftonNew JerseyAS15169 Google LLC07015United Statestier_313lga34s19-in-f4.1e100.netnan
23167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_38nannan
2454.205.240.192AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_37ec2-54-205-240-192.compute-1.amazonaws.comnan
25100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_37pool-100-37-135-2.nycmny.fios.verizon.netnan
26172.217.11.36New York CityNew YorkAS15169 Google LLC10004United Statestier_37lga25s61-in-f4.1e100.netnan
27161.35.60.200North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_36nannan
28172.217.11.4New York CityNew YorkAS15169 Google LLC10004United Statestier_35lga25s60-in-f4.1e100.netnan
29157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_35nannan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website