Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0257257111201392021-04-0137.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_1helloboss.in1Dynadot LLCns1.commonmx.comNone
1tier_1drehscheibe-deutschland.de1NoneNoneNone
2tier_1fotospornocaseras.net1SNAPNAMES 81, LLCNS1.COMMONMX.COMNone
3tier_1bbffs.com1Long Drive Domains LLCNS1.COMMONMX.COMNone
4tier_1aurbataao.com1NoneNoneNone
5tier_1gidporno.com1NoneNoneNone
6tier_1airtemail.in1Dynadot LLCns1.commonmx.comNone
7tier_1katrill.com1NoneNoneNone
8tier_1genesisblogs.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1mainerailtransit.org1Deschutesdomains.com LLCNS1.COMMONMX.COMNone
10tier_21496.wcitianka.com183GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
11tier_2americanlisted.com182ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
12tier_29nl.es80NoneNoneNone
13tier_2newre-conversions.clickmeter.com80REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
14tier_2ring.joveo.com80Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
15tier_2turibius-hra.com20Amazon Registrar, Inc.NS-1142.AWSDNS-14.ORGWhois Privacy Service
16tier_2btpnav.com111API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
17tier_2rd.bizrate.com6MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
18tier_2noclick.connexity.com5MarkMonitor Inc.NS-1235.AWSDNS-26.ORGNone
19tier_2rd.connexity.net5NoneNoneNone
20tier_3google.com102MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
21tier_3signup.surveyvoices.com80GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMNone
22tier_3storystudio.sfgate.com6CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
23tier_3wayfair.com5MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
24tier_3m.placesiteb.xyz3Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
25tier_3htvnativeadsolutions.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Television Inc.
26tier_3win4.trustedpush.com1NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
27tier_3theory.com1CSC CORPORATE DOMAINS, INC.NS0.DNSMADEEASY.COMTheory LLC
28tier_3americanlisted.com1ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
29tier_3bing.com1MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216RevereMassachusettsAS30633 Leaseweb USA, Inc.02151United Statestier_131nannan
1207.244.67.214RevereMassachusettsAS30633 Leaseweb USA, Inc.02151United Statestier_130nannan
2207.244.67.215RevereMassachusettsAS30633 Leaseweb USA, Inc.02151United Statestier_128nannan
3207.244.67.218RevereMassachusettsAS30633 Leaseweb USA, Inc.02151United Statestier_122nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_115nannan
5104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
6206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
882.192.82.225AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
937.48.65.148SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_15nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_2183nannan
1135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_2182240.61.209.35.bc.googleusercontent.comnan
1223.21.166.230AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_245ec2-23-21-166-230.compute-1.amazonaws.comnan
1323.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_243ec2-23-21-53-13.compute-1.amazonaws.comnan
1454.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_237ec2-54-235-205-204.compute-1.amazonaws.comnan
1554.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_235ec2-54-197-247-190.compute-1.amazonaws.comnan
1613.225.230.122New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_223server-13-225-230-122.jfk51.r.cloudfront.netnan
1713.225.230.105New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_223server-13-225-230-105.jfk51.r.cloudfront.netnan
1813.225.230.128New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_219server-13-225-230-128.jfk51.r.cloudfront.netnan
1913.225.230.11New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_215server-13-225-230-11.jfk51.r.cloudfront.netnan
20104.21.71.177San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_347nanTrue
21172.67.147.244San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_333nanTrue
22172.217.165.132New York CityNew YorkAS15169 Google LLC10004United Statestier_321lga25s70-in-f4.1e100.netnan
23172.217.3.100WestburyNew YorkAS15169 Google LLC11590United Statestier_319lga34s18-in-f4.1e100.netnan
24142.250.64.68Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_319lga34s30-in-f4.1e100.netnan
25142.250.64.100Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_313lga34s31-in-f4.1e100.netnan
26142.250.80.4New York CityNew YorkAS15169 Google LLC10004United Statestier_311lga34s33-in-f4.1e100.netnan
27172.217.10.100CliftonNew JerseyAS15169 Google LLC07015United Statestier_311lga34s15-in-f4.1e100.netnan
28172.217.9.228CliftonNew JerseyAS15169 Google LLC07015United Statestier_38lga34s11-in-f4.1e100.netnan
2998.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_36nannan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website