Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
025527413160192021-04-1037.48.65.149Chrome
tierdomaincountregistrarname_serversorg
0tier_1bunkerkilts.com1Communigal Communication LtdNS1.COMMONMX.COMNone
1tier_1allbank.co.in1Dynadot LLCns1.commonmx.comNone
2tier_1campusesolution.com1NoneNoneNone
3tier_1aktivwatch.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1aweldaw.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
5tier_1freecodes.co1GoDaddy.com, LLCns2.commonmx.comNone
6tier_1animeseason.co1Dynadot LLCns2.commonmx.comNone
7tier_1coutellerie-gallo.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159500188
8tier_1firmfile.us1Communigal Communication Ltdns2.commonmx.comNone
9tier_1emeksitesi.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158850488
10tier_2btpnav.com931API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aristo-hag.com53Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_2ads35.adtelligent.com50DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
13tier_2dsp35.adtelligent.com50DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
14tier_2aldb1.mysearch.space49NoneNoneNone
15tier_2externals-1953518744.us-east-1.elb.amazonaws.com49MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
16tier_2search.snjsearch.com49GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2click.expmediadirect.com44NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
18tier_21496.rawlexi.com42GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
19tier_2americanlisted.com40ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
20tier_2traff0121.com20NAMECHEAP INCHANS.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
21tier_2contentgate.uno20NoneNoneNone
22tier_20.contentgate.uno20NoneNoneNone
23tier_21.contentgate.uno18NoneNoneNone
24tier_22.contentgate.uno17NoneNoneNone
25tier_2seekallanswrs.com16NameSilo, LLCNS-CLOUD-A1.GOOGLEDOMAINS.COMSee PrivacyGuardian.org
26tier_2quicki-search.com16GoDaddy.com, LLCNS29.DOMAINCONTROL.COMDomains By Proxy, LLC
27tier_2surfisnow.com15GoDaddy.com, LLCDNS1.P09.NSONE.NETClientConnect LTD
28tier_2btpnative.com141API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
29tier_2infopicked.com14NoneNoneNone
30tier_3bing.com46MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
31tier_3aliexpress.com_LOOP_113NoneNoneNone
32tier_3us.tideri.com12united domains AGNS.UDAG.DENone
33tier_3api.readysetforfineplayer.com7NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
34tier_3upward.careers7GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
35tier_3ram21.proasdf.com5GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
36tier_3driverfixersoftware.com4TLDS LLC. d/b/a SRSPlusNINA.NS.CLOUDFLARE.COMNone
37tier_3rd.bizrate.com4MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
38tier_33.contentgate.uno4NoneNoneNone
39tier_3us.allthetopbananas.com4ENOM, INC.DANE.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
40tier_3dollarshaveclub.com3GoDaddy.com, LLCNS-1465.AWSDNS-55.ORGDomains By Proxy, LLC
41tier_3chrismoneymaker.com3GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
42tier_3google.com_LOOP_13NoneNoneNone
43tier_3toryburch.com3CSC CORPORATE DOMAINS, INC.DNS1.CSCDNS.NETRiver Light V, L.P.
44tier_3careers.homedepot.com3CSC CORPORATE DOMAINS, INC.A1-27.AKAM.NETHome Depot Product Authority, LLC
45tier_3click.appcast.io_LOOP_13NoneNoneNone
46tier_3click.appcast.io3101Domain GRS LtdNS-85.AWSDNS-10.COMNone
47tier_3filter.onwardclick.com2NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
48tier_31.contentgate.uno2NoneNoneNone
49tier_3americanlisted.com2ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
50tier_3find.search-armor.com2GoDaddy.com, LLCDNS1.P09.NSONE.NETDomains By Proxy, LLC
51tier_3reebok.com2CSC CORPORATE DOMAINS, INC.NS1.NETNAMES.NETReebok International, Ltd.
52tier_3cehappear.fun1DYNADOT LLCAIDEN.NS.CLOUDFLARE.COMNone
53tier_3surfisnow.com1GoDaddy.com, LLCDNS1.P09.NSONE.NETClientConnect LTD
54tier_3signup.finddreamjobs.com1GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
55tier_3jobs.massageenvy.com1Network Solutions, LLCNS1.WORLDNIC.COMNone
56tier_3google.com1MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
57tier_3trk.careerbliss.com1GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
58tier_3nizephoros-pom.com1Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
59tier_3portlandjobsite.com1ENOM, INC.DNS1.NAME-SERVICES.COMREDACTED FOR PRIVACY
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
3207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_114nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_18nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
874.63.241.28DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1328-241-63-74.static.reverse.lstn.netnan
937.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2109nannan
11178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_37nannan
12209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_250static-42-202-205-209.24shells.netnan
13209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_250static-43-202-205-209.24shells.netnan
1435.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_249ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
15198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_244nannan
16198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nannan
1735.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_32240.61.209.35.bc.googleusercontent.comnan
1888.99.101.106Hohen NeuendorfBrandenburgAS24940 Hetzner Online GmbH16540Germanytier_233static.106.101.99.88.clients.your-server.denan
1952.29.135.45Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_228ec2-52-29-135-45.eu-central-1.compute.amazonaws.comnan
2050.16.173.246AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_225ec2-50-16-173-246.compute-1.amazonaws.comnan
2154.210.170.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_224ec2-54-210-170-165.compute-1.amazonaws.comnan
223.125.109.211Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_222ec2-3-125-109-211.eu-central-1.compute.amazonaws.comnan
2335.226.116.123Council BluffsIowaAS15169 Google LLC51502United Statestier_216123.116.226.35.bc.googleusercontent.comnan
24216.239.36.21Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_215nanTrue
25173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21418.65.c0ad.ip4.static.sl-reverse.comnan
26192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_34nannan
2754.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213ec2-54-208-107-202.compute-1.amazonaws.comnan
2834.231.10.22AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-34-231-10-22.compute-1.amazonaws.comnan
29216.239.32.21Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_212any-in-2015.1e100.netTrue
30204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_336a-0001.a-msedge.netTrue
31100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_319pool-100-37-135-2.nycmny.fios.verizon.netnan
3235.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_312123.171.246.35.bc.googleusercontent.comnan
3313.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_310nanTrue
345.2.76.193DrontenFlevolandAS60404 Liteserver8254Netherlandstier_37mflexing.xyznan
35178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_37nannan
3667.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_37nannan
37162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_35nannan
38192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_34nannan
39151.101.1.9San FranciscoCaliforniaAS54113 Fastly94107United Statestier_33nanTrue
4092.205.4.117StrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_33ip-92-205-4-117.ip.secureserver.netnan
41104.21.83.108San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
42104.26.12.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
43173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_32nannan
4435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_32240.61.209.35.bc.googleusercontent.comnan
4599.84.47.119NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-47-119.ewr52.r.cloudfront.netnan
4623.40.23.148PhiladelphiaPennsylvaniaAS16625 Akamai Technologies, Inc.19099United Statestier_32a23-40-23-148.deploy.static.akamaitechnologies.comnan
4799.84.189.25WashingtonWashington, D.C.AS16509 Amazon.com, Inc.20045United Statestier_31server-99-84-189-25.iad89.r.cloudfront.netnan
48172.67.223.119San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
4913.33.46.128NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-13-33-46-128.ewr52.r.cloudfront.netnan
50104.77.178.158EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_31a104-77-178-158.deploy.static.akamaitechnologies.comnan
51104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5223.59.250.96NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a23-59-250-96.deploy.static.akamaitechnologies.comnan
5323.38.170.185NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a23-38-170-185.deploy.static.akamaitechnologies.comnan
54172.217.165.132New York CityNew YorkAS15169 Google LLC10004United Statestier_31lga25s70-in-f4.1e100.netnan
55207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_31cbsmtp1.careerbliss.comnan
5699.84.114.106NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-106.ewr52.r.cloudfront.netnan
5752.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-3-4-129.compute-1.amazonaws.comnan
583.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-3-234-0-165.compute-1.amazonaws.comnan
5934.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-34-207-43-7.compute-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website