Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
028329511400232021-04-1237.48.65.149Iphone
tierdomaincountregistrarname_serversorg
0tier_1gurrenlagannepisodes.com1Domainsofvalue.com LLCNS1.COMMONMX.COMNone
1tier_1kadraya.net1Fastball Domains LLCNS1.COMMONMX.COMNone
2tier_1grupocoop.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1filemp3.mobi1DYNADOT LLCNoneNone
4tier_1hablon.biz1GoDaddy.com, LLCns2.commonmx.comNone
5tier_1iniciandoenbolsa.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158499277
6tier_1e-mali.mobi1DYNADOT LLCNoneNone
7tier_1korealit.net1Go Australia Domains, LLCNS1.COMMONMX.COMNone
8tier_1decal4bike.net1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159836770
9tier_1dd-routers.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2aristo-hag.com69Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2click.expmediadirect.com68NoneNoneNone
12tier_2btpnav.com611API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
13tier_2ads35.adtelligent.com32DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
14tier_2dsp35.adtelligent.com32DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
15tier_2aibm1.mysearch.space32NoneNoneNone
16tier_2externals-1953518744.us-east-1.elb.amazonaws.com31MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
17tier_2search.snjsearch.com31GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
18tier_2search-checker.com30Name.com, Inc.BETH.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
19tier_2m.onlineweb.mobi30GoDaddy.com, LLCNoneNone
20tier_2api.quotes.com28Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
21tier_2changeslots.com28Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
22tier_2clk.rtpdn12.com20NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
23tier_2api.apptap.com16Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
24tier_2exporimy.com15GoDaddy.com, LLCNS-1145.AWSDNS-15.ORGDomains By Proxy, LLC
25tier_2sorrectionki.space15NoneNoneNone
26tier_2rqhere2.com13NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
27tier_2api.mplayit.com12Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
28tier_2redirect.viglink.com12Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
29tier_2link.sylikes.com12MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
30tier_3bestappland.me42NAMECHEAP INCNoneNone
31tier_3bing.com31MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
32tier_3theconnectvpn.com28DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
33tier_3irl.com17GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
34tier_3storystudio.sfgate.com12CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
35tier_3tackis.xyz11NAMECHEAP INCPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
36tier_3apple.com6CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
37tier_3venus.com6GoDaddy.com, LLCNS0.DNSMADEEASY.COMVenus Fashion, Inc.
38tier_3bestbody.s3.amazonaws.com4MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
39tier_3rd.bizrate.com3NoneNoneNone
40tier_3shopnsave.world3NoneNoneNone
41tier_3gramp.xyz3NAMECHEAP INCDAVID.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
42tier_3bitdefender.com2Register.com, Inc.PDNS210.ULTRADNS.BIZStatutory Masking Enabled
43tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
44tier_3apple.news2NoneNoneNone
45tier_3wayfair.com2MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
46tier_3filter.onwardclick.com2NoneNoneNone
47tier_3venus.com_LOOP_12NoneNoneNone
48tier_3orthofeet.com1Network Solutions, LLCNS27.WORLDNIC.COMORTHOFEET INC.
49tier_3bedbathandbeyond.com1Network Solutions, LLCA1-189.AKAM.NETBed Bath & Beyond Procurement Co. Inc.
50tier_3m.northerntool.com1Network Solutions, LLCA.NS.NORTHERNTOOL.COMNone
51tier_3beyourxfriend.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
52tier_3rpa21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
53tier_3thelastpicture.show1NoneNoneNone
54tier_3bulley.shop1NAMECHEAP INCDAVID.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
55tier_3externals-1953518744.us-east-1.elb.amazonaws.com1MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
56tier_3click.appcast.io1101Domain GRS LtdNS-85.AWSDNS-10.COMNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_133nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
3207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
4206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_117nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
8185.107.56.199RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
9185.107.56.197RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_274nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_268nannan
12209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_232static-42-202-205-209.24shells.netnan
13209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_232static-43-202-205-209.24shells.netnan
14173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_32nannan
1535.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_231ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
165.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_228nannan
1734.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_228ec2-34-207-32-33.compute-1.amazonaws.comnan
18192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33nannan
1952.29.135.45Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_220ec2-52-29-135-45.eu-central-1.compute.amazonaws.comnan
20104.21.41.235San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_220nanTrue
21192.241.228.85San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_217nannan
2254.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_217ec2-54-208-107-202.compute-1.amazonaws.comnan
2352.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_216ec2-52-72-29-7.compute-1.amazonaws.comnan
2454.210.170.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_216ec2-54-210-170-165.compute-1.amazonaws.comnan
25209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_216nannan
2650.16.173.246AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_215ec2-50-16-173-246.compute-1.amazonaws.comnan
2734.202.14.39AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_215ec2-34-202-14-39.compute-1.amazonaws.comnan
28192.241.229.243San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_214nannan
2918.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_214ec2-18-235-67-128.compute-1.amazonaws.comnan
30142.93.4.215North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_342nannan
31204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_323a-0001.a-msedge.netTrue
32104.21.91.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314nanTrue
33172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314nanTrue
34151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_310nanTrue
3513.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_38nanTrue
36172.67.189.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
37184.85.12.70NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_36a184-85-12-70.deploy.static.akamaitechnologies.comnan
3823.201.24.53NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_35a23-201-24-53.deploy.static.akamaitechnologies.comnan
39104.21.65.93San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
40100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_34pool-100-37-135-2.nycmny.fios.verizon.netnan
41192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33nannan
4254.205.240.192AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-54-205-240-192.compute-1.amazonaws.comnan
4352.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-52-73-153-209.compute-1.amazonaws.comnan
44167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
4567.227.241.125LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_33nannan
46162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_33nannan
47104.21.92.190San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
4823.39.32.237NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-39-32-237.deploy.static.akamaitechnologies.comnan
4964.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
50173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_32nannan
5123.227.38.74OttawaOntarioAS13335 Cloudflare, Inc.K2PCanadatier_31nanTrue
5223.41.190.46NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-190-46.deploy.static.akamaitechnologies.comnan
53104.18.169.222San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5423.38.172.250NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-38-172-250.deploy.static.akamaitechnologies.comnan
55157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
56104.17.87.80San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5752.217.163.217AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1-w.amazonaws.comnan
58104.18.168.222San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5945.33.8.244RichardsonTexasAS63949 Linode, LLC75080United Statestier_31li962-244.members.linode.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website