Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02432437690162021-04-1337.48.65.149Safari
tierdomaincountregistrarname_serversorg
0tier_1acnedoctor.us1Communigal Communication Ltdns2.commonmx.comNone
1tier_1daily-news.us1Dynadot LLCns2.commonmx.comNone
2tier_1goresults.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1cotact.us1Communigal Communication Ltdns2.commonmx.comNone
4tier_1comefly.us1Communigal Communication Ltdns2.commonmx.comNone
5tier_1coinhackgame.us1GoDaddy.com, LLCns2.commonmx.comNone
6tier_1asio.pro1DYNADOT LLCNS1.COMMONMX.COMNone
7tier_1alriyadh.us1Communigal Communication Ltdns2.commonmx.comNone
8tier_1consecratiomundi.us1Communigal Communication Ltdns2.commonmx.comNone
9tier_1azulholisticspa.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
10tier_21496.rawlexi.com176GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
11tier_2btpnav.com421API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2americanlisted.com40ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
13tier_29nl.es14NoneNoneNone
14tier_2newre-conversions.clickmeter.com14REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
15tier_2trk.jometer.com13Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
16tier_2api.l5srv.net13GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2nizephoros-pom.com9Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
18tier_2us.expand-backend.mindmatch.ai8NoneNoneNone
19tier_2managerformula.com8NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
20tier_2click.appcast.io6101Domain GRS LtdNS-85.AWSDNS-10.COMNone
21tier_2click.expmediadirect.com3NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
22tier_2api.apptap.com3Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
23tier_2redirect.viglink.com3Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
24tier_2link.sylikes.com3MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
25tier_2api.mplayit.com2Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
26tier_2folcher-cri.com2Amazon Registrar, Inc.NS-1201.AWSDNS-22.ORGWhois Privacy Service
27tier_2productiq.net2GoDaddy.com, LLCDOUG.NS.CLOUDFLARE.COMDomains By Proxy, LLC
28tier_2rd.bizrate.com2NoneNoneNone
29tier_2rd.connexity.net2NoneNoneNone
30tier_3americanlisted.com135ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
31tier_3upward.careers13GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
32tier_3us.tideri.com12united domains AGNS.UDAG.DENone
33tier_3s3.amazonaws.com9MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
34tier_3us.allthetopbananas.com8ENOM, INC.DANE.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
35tier_3careerbuilder.com3CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
36tier_3linkedin.com1MarkMonitor, Inc.DNS1.P09.NSONE.NETLinkedIn Corporation
37tier_3google.com_LOOP_11NoneNoneNone
38tier_3reebok.com1CSC CORPORATE DOMAINS, INC.NS1.NETNAMES.NETReebok International, Ltd.
39tier_3ram21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
40tier_3dell.com1Safenames LtdNS1.US.DELL.COMNone
41tier_3eharmony.com1NoneNoneNone
42tier_3signup.careersandjobs.co1GoDaddy.com, LLCalexis.ns.cloudflare.comDomains By Proxy, LLC
43tier_3jobleads.com1united domains AGCRUZ.NS.CLOUDFLARE.COMNone
44tier_3click.appcast.io1101Domain GRS LtdNS-85.AWSDNS-10.COMNone
45tier_3rd.bizrate.com1MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
46tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETMacy's Systems and Technology, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
3207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_118nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_117nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
882.192.82.226AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
974.63.241.20DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1320-241-63-74.static.reverse.lstn.netnan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_2176nannan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_243nannan
1235.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_3135240.61.209.35.bc.googleusercontent.comnan
1367.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_213nannan
1423.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-23-21-53-13.compute-1.amazonaws.comnan
1523.21.166.230AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-23-21-166-230.compute-1.amazonaws.comnan
1634.120.235.106Kansas CityMissouriAS15169 Google LLC64121United Statestier_28106.235.120.34.bc.googleusercontent.comTrue
1799.84.114.25NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_26server-99-84-114-25.ewr52.r.cloudfront.netnan
1854.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-54-197-247-190.compute-1.amazonaws.comnan
19159.127.43.26WashingtonWashington, D.C.AS25751 Conversant, Inc.20045United Statestier_26nannan
2052.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-52-72-29-7.compute-1.amazonaws.comnan
21192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31nannan
2254.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-54-208-107-202.compute-1.amazonaws.comnan
2354.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-54-235-205-204.compute-1.amazonaws.comnan
24100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-100-25-52-1.compute-1.amazonaws.comnan
2599.84.114.65NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_23server-99-84-114-65.ewr52.r.cloudfront.netnan
26198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_23nannan
2752.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-52-206-141-190.compute-1.amazonaws.comnan
2899.84.114.17NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_23server-99-84-114-17.ewr52.r.cloudfront.netnan
2934.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-34-225-128-119.compute-1.amazonaws.comnan
3035.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_3135240.61.209.35.bc.googleusercontent.comnan
3167.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_313nannan
3235.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_312123.171.246.35.bc.googleusercontent.comnan
33104.26.12.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
3452.216.83.91AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
3552.216.135.13AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
3652.216.249.182AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
3713.107.42.14RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31nanTrue
38100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_31pool-100-37-135-2.nycmny.fios.verizon.netnan
3952.217.200.240AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
4023.201.27.178NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-201-27-178.deploy.static.akamaitechnologies.comnan
4199.84.114.78NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-78.ewr52.r.cloudfront.netnan
42162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_31nannan
4399.84.114.91NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-91.ewr52.r.cloudfront.netnan
44184.87.86.140NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-87-86-140.deploy.static.akamaitechnologies.comnan
4552.216.18.59AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
4652.216.78.86AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
47104.16.8.138San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
48104.21.10.65San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
49194.6.195.224HamburgHamburgAS39227 Corpex Internet GmbH20038Germanytier_31www.jobleads.denan
503.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-3-234-0-165.compute-1.amazonaws.comnan
51104.26.13.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5299.84.114.84NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-84.ewr52.r.cloudfront.netnan
53192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31nannan
5423.41.189.63NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-63.deploy.static.akamaitechnologies.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website