Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
027728311590202021-04-1537.48.65.149Iphone
tierdomaincountregistrarname_serversorg
0tier_1hochkrimmel.de1NoneNoneNone
1tier_1im7love.com1Cool River Names, LLCNS1.COMMONMX.COMNone
2tier_1pods.info1DYNADOT LLCNS1.COMMONMX.COMNone
3tier_1bidguru.in1Dynadot LLCns1.commonmx.comNone
4tier_1hablon.biz1GoDaddy.com, LLCns2.commonmx.comNone
5tier_1mukdahan.org1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1kurzgeschichten.biz1GoDaddy.com, LLCns2.commonmx.comNone
7tier_1nctvnews.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
8tier_1iori-yagami.mobi1DYNADOT LLCNoneNone
9tier_1desaqq.info1DYNADOT LLCNS1.COMMONMX.COMNone
10tier_2aristo-hag.com62Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2btpnav.com531API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2click.expmediadirect.com47NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
13tier_2ads35.adtelligent.com42DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
14tier_2dsp35.adtelligent.com42DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
15tier_2aibm1.mysearch.space42NoneNoneNone
16tier_2externals-1953518744.us-east-1.elb.amazonaws.com42MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
17tier_2search.snjsearch.com42GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
18tier_2search-checker.com41Name.com, Inc.BETH.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
19tier_2m.onlineweb.mobi41GoDaddy.com, LLCNoneNone
20tier_2api.quotes.com27Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
21tier_2changeslots.com27Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
22tier_21496.rawlexi.com21GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
23tier_2americanlisted.com17ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
24tier_2clk.rtpdn12.com17NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
25tier_2exporimy.com15GoDaddy.com, LLCNS-1145.AWSDNS-15.ORGDomains By Proxy, LLC
26tier_2sorrectionki.space15NoneNoneNone
27tier_2apptime.xyz13NAMECHEAP INCPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
28tier_2api.apptap.com12Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
29tier_2redirect.viglink.com12Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
30tier_3bing.com42MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
31tier_3bestappland.me30NAMECHEAP INCNoneNone
32tier_3theconnectvpn.com27DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
33tier_3tackis.xyz13NAMECHEAP INCPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
34tier_3storystudio.sfgate.com8CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
35tier_3google.com7MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
36tier_3music.apple.com6CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
37tier_3americanlisted.com4ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
38tier_3fanatics.com4MarkMonitor Inc.A1-147.AKAM.NETNone
39tier_3chrismoneymaker.com3GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
40tier_3click.appcast.io2101Domain GRS LtdNS-85.AWSDNS-10.COMNone
41tier_3beyourxfriend.com2GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
42tier_3java.limitedtopoffers.com21&1 IONOS SERORY.NS.CLOUDFLARE.COM1&1 Internet Inc
43tier_3toryburch.com2CSC CORPORATE DOMAINS, INC.DNS1.CSCDNS.NETRiver Light V, L.P.
44tier_3bulley.shop2NAMECHEAP INCDAVID.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
45tier_3rd.bizrate.com2MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
46tier_3grandinroad.com_LOOP_21NoneNoneNone
47tier_3rpa21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
48tier_3land.driverapponline.com1NoneNoneNone
49tier_3roamans.com1CSC CORPORATE DOMAINS, INC.PDNS1.ULTRADNS.NETFullBeauty Brands Operations, LLC
50tier_3signup.careersandjobs.co1GoDaddy.com, LLCalexis.ns.cloudflare.comDomains By Proxy, LLC
51tier_3ads.midwayusa.com1GoDaddy.com, LLCNS-1486.AWSDNS-57.ORGMidwayUSA
52tier_3careerbuilder.com1CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
53tier_363086.click.validclick.net1Safenames LtdNS1.FULLMAILBOX.COMNone
54tier_3upward.careers1GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
55tier_3reebok.com_LOOP_11NoneNoneNone
56tier_3primeinc.com1Network Solutions, LLCNS-1507.AWSDNS-60.ORGNone
57tier_3linkedin.com1MarkMonitor, Inc.DNS1.P09.NSONE.NETLinkedIn Corporation
58tier_3shopnsave.world1NoneNoneNone
59tier_3getstarjobs.getitcorporate.com1GoDaddy.com, LLCNS-CLOUD-E1.GOOGLEDOMAINS.COMGet It LLC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_131nannan
1207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_117nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
837.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
937.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_265nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_247nannan
12209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_242static-42-202-205-209.24shells.netnan
13209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_242static-43-202-205-209.24shells.netnan
1435.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_242ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
155.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_227nannan
1634.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_227ec2-34-207-32-33.compute-1.amazonaws.comnan
17172.67.196.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_224nanTrue
18192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_32rd.bizrate.comnan
193.125.109.211Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_223ec2-3-125-109-211.eu-central-1.compute.amazonaws.comnan
20192.241.228.85San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_223nannan
2150.16.173.246AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-50-16-173-246.compute-1.amazonaws.comnan
22198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_221nannan
2354.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_220ec2-54-208-107-202.compute-1.amazonaws.comnan
2454.210.170.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_220ec2-54-210-170-165.compute-1.amazonaws.comnan
2552.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_219ec2-52-72-29-7.compute-1.amazonaws.comnan
26192.241.229.243San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_219nannan
2752.29.135.45Frankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_219ec2-52-29-135-45.eu-central-1.compute.amazonaws.comnan
28173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_219nannan
2935.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_34240.61.209.35.bc.googleusercontent.comnan
30204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_336a-0001.a-msedge.netTrue
31142.93.4.215North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_330nannan
32172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_315nanTrue
33104.21.91.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_312nanTrue
34151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_38nanTrue
35100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_38pool-100-37-135-2.nycmny.fios.verizon.netnan
36172.67.189.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
3713.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_36nanTrue
38104.21.65.93San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_36nanTrue
39172.217.12.196CliftonNew JerseyAS15169 Google LLC07015United Statestier_34lga25s63-in-f4.1e100.netnan
4035.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_34240.61.209.35.bc.googleusercontent.comnan
4192.205.4.117StrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_33ip-92-205-4-117.ip.secureserver.netnan
42172.217.6.228Clinton CornersNew YorkAS15169 Google LLC12514United Statestier_33lga25s55-in-f228.1e100.netnan
43184.87.65.240NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a184-87-65-240.deploy.static.akamaitechnologies.comnan
4445.33.8.244RichardsonTexasAS63949 Linode, LLC75080United Statestier_32li962-244.members.linode.comnan
45162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
46104.21.28.174San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4723.59.250.96NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_32a23-59-250-96.deploy.static.akamaitechnologies.comnan
48172.67.134.131San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
49192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_32rd.bizrate.comnan
5052.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-3-4-129.compute-1.amazonaws.comnan
51104.18.22.245San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
523.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-3-234-0-165.compute-1.amazonaws.comnan
53165.254.198.226DallasTexasAS393259 Yottaa, Inc75270United Statestier_31nannan
54172.67.144.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5523.32.160.166New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31a23-32-160-166.deploy.static.akamaitechnologies.comnan
5699.84.114.84NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-84.ewr52.r.cloudfront.netnan
57204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_31204.44.79.214.static.quadranet.comnan
5867.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_31nannan
5935.184.50.134Council BluffsIowaAS15169 Google LLC51502United Statestier_31134.50.184.35.bc.googleusercontent.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website