Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02562516410152021-04-1337.48.65.149Android
tierdomaincountregistrarname_serversorg
0tier_1acnedoctor.us1Communigal Communication Ltdns2.commonmx.comNone
1tier_1daily-news.us1Dynadot LLCns2.commonmx.comNone
2tier_1goresults.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1cotact.us1Communigal Communication Ltdns2.commonmx.comNone
4tier_1comefly.us1Communigal Communication Ltdns2.commonmx.comNone
5tier_1coinhackgame.us1GoDaddy.com, LLCns2.commonmx.comNone
6tier_1asio.pro1Dynadot, LLCNS1.COMMONMX.COMNone
7tier_1alriyadh.us1Communigal Communication Ltdns2.commonmx.comNone
8tier_1consecratiomundi.us1Communigal Communication Ltdns2.commonmx.comNone
9tier_1azulholisticspa.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
10tier_21496.rawlexi.com173GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
11tier_2aristo-hag.com6Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_2click.expmediadirect.com4NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
13tier_2api.apptap.com4Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
14tier_2api.mplayit.com4Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
15tier_2redirect.viglink.com4Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
16tier_2link.sylikes.com4MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
17tier_2rd.bizrate.com4NoneNoneNone
18tier_2rd.connexity.net4NoneNoneNone
19tier_2btpnav.com31API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
20tier_262813.click.validclick.net2Safenames LtdNS1.FULLMAILBOX.COMNone
21tier_2rtbstream.com21API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
22tier_2jdoqocy.com2MarkMonitor, Inc.ASIA9.AKAM.NETConversant, Inc.
23tier_2cj.dotomi.com2GoDaddy.com, LLCASIA9.AKAM.NETConversant LLC
24tier_2emjcd.com2MarkMonitor, Inc.ASIA9.AKAM.NETConversant, Inc.
25tier_2v4.s.arclk.net2PSI-USA, Inc. dba Domain RobotA.NS14.NETNone
26tier_2r.lnk8j7.com21&1 IONOS SENS-1314.AWSDNS-36.ORG1&1 Internet Limited
27tier_2lg.provenpixel.com21&1 IONOS SENS01.PROVENPIXEL.NET1&1 Internet Inc
28tier_2api.apptap.com_LOOP_12NoneNoneNone
29tier_2xml.onwardclick.com1NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
30tier_3americanlisted.com173ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
31tier_3storystudio.sfgate.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
32tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
33tier_3filter.onwardclick.com1NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
34tier_3orthofeet.com1Network Solutions, LLCNS27.WORLDNIC.COMORTHOFEET INC.
35tier_3ads.midwayusa.com1GoDaddy.com, LLCNS-1486.AWSDNS-57.ORGMidwayUSA
36tier_3dell.com1Safenames LtdNS1.US.DELL.COMNone
37tier_3a.dollarsurvey365.online1URL Solutions Inc.CRYSTAL.NS.CLOUDFLARE.COMNone
38tier_3bing.com1MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
39tier_3blair.com1CSC CORPORATE DOMAINS, INC.NS-1237.AWSDNS-26.ORGBluestem Brands, Inc.
40tier_3win3.trustedpush.com1NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
41tier_3eharmony.com1NoneNoneNone
42tier_3m.gladplacespin.xyz1NoneNoneNone
43tier_3rd.bizrate.com1MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
44tier_3m.northerntool.com1Network Solutions, LLCA.NS.NORTHERNTOOL.COMNorthern Tool & Equipment Company, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_125nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
7206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
837.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
9185.107.56.197RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_2173nannan
11192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31nannan
1252.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-52-206-141-190.compute-1.amazonaws.comnan
13209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_26nannan
14159.127.43.26WashingtonWashington, D.C.AS25751 Conversant, Inc.20045United Statestier_26nannan
1534.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-34-197-176-2.compute-1.amazonaws.comnan
16198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_24nannan
17192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_24rd.connexity.netnan
18204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_23204.44.79.214.static.quadranet.comnan
1934.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-34-225-128-119.compute-1.amazonaws.comnan
2099.84.114.98NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-98.ewr52.r.cloudfront.netnan
21173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
223.226.191.120AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-3-226-191-120.compute-1.amazonaws.comnan
23185.170.102.1MiamiFloridaAS45028 Barefruit Ltd.33102United Statestier_22nannan
24100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_22pool-100-37-135-2.nycmny.fios.verizon.netnan
2552.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-52-205-177-114.compute-1.amazonaws.comnan
26192.138.218.215SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_21noclick.connexity.comnan
27216.139.248.127AustinTexasAS32400 Hostway Services, Inc.78701United Statestier_21216-139-248-127.aus.us.siteprotect.comnan
28172.217.11.38New York CityNew YorkAS15169 Google LLC10004United Statestier_21lga25s61-in-f6.1e100.netnan
2918.210.251.118AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-18-210-251-118.compute-1.amazonaws.comnan
3035.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_3173240.61.209.35.bc.googleusercontent.comnan
31151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_33nanTrue
32162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
33173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
3423.227.38.74OttawaOntarioAS13335 Cloudflare, Inc.K2PCanadatier_31nanTrue
35104.102.136.83EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a104-102-136-83.deploy.static.akamaitechnologies.comnan
36184.87.86.140NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-87-86-140.deploy.static.akamaitechnologies.comnan
37172.67.72.49San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
3813.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31nanTrue
39184.85.25.250NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-85-25-250.deploy.static.akamaitechnologies.comnan
4099.84.114.98NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-98.ewr52.r.cloudfront.netnan
41104.16.11.138San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
42104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
43192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31nannan
44104.17.90.80San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website