Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
028229110600162021-04-1337.48.65.149Iphone
tierdomaincountregistrarname_serversorg
0tier_1acnedoctor.us1Communigal Communication Ltdns2.commonmx.comNone
1tier_1daily-news.us1Dynadot LLCns2.commonmx.comNone
2tier_1goresults.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1cotact.us1Communigal Communication Ltdns2.commonmx.comNone
4tier_1comefly.us1Communigal Communication Ltdns2.commonmx.comNone
5tier_1coinhackgame.us1GoDaddy.com, LLCns2.commonmx.comNone
6tier_1asio.pro1DYNADOT LLCNS1.COMMONMX.COMNone
7tier_1alriyadh.us1Communigal Communication Ltdns2.commonmx.comNone
8tier_1consecratiomundi.us1Communigal Communication Ltdns2.commonmx.comNone
9tier_1azulholisticspa.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
10tier_2click.expmediadirect.com63NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
11tier_21496.rawlexi.com51GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
12tier_2aristo-hag.com46Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
13tier_2btpnav.com421API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
14tier_2ads35.adtelligent.com25DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
15tier_2dsp35.adtelligent.com25DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
16tier_2aibm1.mysearch.space25NoneNoneNone
17tier_2externals-1953518744.us-east-1.elb.amazonaws.com25MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
18tier_2search.snjsearch.com25GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
19tier_2search-checker.com24Name.com, Inc.BETH.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
20tier_2m.onlineweb.mobi24GoDaddy.com, LLCNoneNone
21tier_2api.apptap.com24Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
22tier_2redirect.viglink.com23Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
23tier_2link.sylikes.com23MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
24tier_2rd.bizrate.com21MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
25tier_2api.quotes.com20Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
26tier_2rd.connexity.net19NoneNoneNone
27tier_2changeslots.com19Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
28tier_2api.mplayit.com16Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
29tier_2exporimy.com11GoDaddy.com, LLCNS-1145.AWSDNS-15.ORGDomains By Proxy, LLC
30tier_3americanlisted.com51ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
31tier_3bestappland.me31NAMECHEAP INCNoneNone
32tier_3bing.com24MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
33tier_3theconnectvpn.com19DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
34tier_3storystudio.sfgate.com12CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
35tier_3frontgate.com9Network Solutions, LLCNS1.HSN.NETCornerstone Brands, Inc.
36tier_3tackis.xyz7NAMECHEAP INCPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
37tier_3venus.com6GoDaddy.com, LLCNS0.DNSMADEEASY.COMVenus Fashion, Inc.
38tier_3irl.com5GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
39tier_3music.apple.com4CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
40tier_3rd.bizrate.com3MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
41tier_3ram21.proasdf.com3GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
42tier_3gramp.xyz3NAMECHEAP INCDAVID.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
43tier_3coolmambo.com2NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
44tier_3blair.com1CSC CORPORATE DOMAINS, INC.NS-1237.AWSDNS-26.ORGBluestem Brands, Inc.
45tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETNone
46tier_3venus.com_LOOP_11NoneNoneNone
47tier_3wayfair.com1MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
48tier_3filter.onwardclick.com1NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
49tier_3guard-protection.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
50tier_3dell.com1Safenames LtdNS1.US.DELL.COMNone
51tier_3reebok.com1CSC CORPORATE DOMAINS, INC.NS1.NETNAMES.NETReebok International, Ltd.
52tier_3toryburch.com1CSC CORPORATE DOMAINS, INC.DNS1.CSCDNS.NETRiver Light V, L.P.
53tier_3eharmony.com1MarkMonitor, Inc.BECKY.NS.CLOUDFLARE.COMeHarmony, Inc.
54tier_3beyourxfriend.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
55tier_3bulley.shop1NAMECHEAP INCDAVID.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
56tier_3thredup.com1GoDaddy.com, LLCMATT.NS.CLOUDFLARE.COMThredUp Inc.
57tier_3search-checker.com1Name.com, Inc.BETH.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_133nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
3207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
4206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
774.63.241.20DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1520-241-63-74.static.reverse.lstn.netnan
8104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
937.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_263nannan
11198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_251nannan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_249nannan
13192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33nannan
14209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_225static-42-202-205-209.24shells.netnan
15209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_225static-43-202-205-209.24shells.netnan
1635.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_225ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
175.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_220nannan
1818.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_219ec2-18-235-67-128.compute-1.amazonaws.comnan
19192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_219rd.connexity.netnan
2034.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_219ec2-34-207-32-33.compute-1.amazonaws.comnan
2152.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_218ec2-52-205-177-114.compute-1.amazonaws.comnan
22172.67.196.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_217nanTrue
23192.241.229.243San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_216nannan
2454.210.170.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_216ec2-54-210-170-165.compute-1.amazonaws.comnan
25173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
2652.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_215ec2-52-206-141-190.compute-1.amazonaws.comnan
2752.29.135.45Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_215ec2-52-29-135-45.eu-central-1.compute.amazonaws.comnan
2834.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213ec2-34-225-128-119.compute-1.amazonaws.comnan
2952.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-52-72-29-7.compute-1.amazonaws.comnan
3035.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_351240.61.209.35.bc.googleusercontent.comnan
31142.93.4.215North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_331nannan
32204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_317a-0001.a-msedge.netTrue
33151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_312nanTrue
34172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_310nanTrue
35184.87.71.113NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_39a184-87-71-113.deploy.static.akamaitechnologies.comnan
36104.21.91.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_39nanTrue
3713.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_37nanTrue
38100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_37pool-100-37-135-2.nycmny.fios.verizon.netnan
39184.85.12.70NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_36a184-85-12-70.deploy.static.akamaitechnologies.comnan
40104.21.65.93San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
41192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33nannan
42172.67.189.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4364.91.232.212LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_32host.encontext.comnan
44104.21.92.190San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
45157.245.84.7North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
46184.85.25.250NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-85-25-250.deploy.static.akamaitechnologies.comnan
47104.77.220.218New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31a104-77-220-218.deploy.static.akamaitechnologies.comnan
4823.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-99.deploy.static.akamaitechnologies.comnan
49173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_31nannan
50165.227.27.70Santa ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_31nannan
51184.87.86.140NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-87-86-140.deploy.static.akamaitechnologies.comnan
5252.203.36.44AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-203-36-44.compute-1.amazonaws.comnan
53162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_31nannan
54167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
55198.199.66.189North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
5623.201.27.178NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-201-27-178.deploy.static.akamaitechnologies.comnan
57172.232.19.26NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a172-232-19-26.deploy.static.akamaitechnologies.comnan
5864.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
59104.16.7.138San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website