Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02612578891162021-04-1637.48.65.149Chrome
tierdomaincountregistrarname_serversorg
0tier_13waycafe.com1DYNADOT LLCNS1.COMMONMX.COMNone
1tier_1edupromocodes.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158845623
2tier_1filr.io1Dynadot, LLCNS1.COMMONMX.COMNone
3tier_1cdhatver.com1NamePal.com #8010, LLCNS1.COMMONMX.COMNone
4tier_1buysellads.ph1NoneNoneNone
5tier_1avikjain.me1Dynadot, LLCNoneNone
6tier_1chungcucanhogiare.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1akorv.me1GoDaddy.com, LLCNoneNone
8tier_1aicaiwang.me1GoDaddy.com, LLCNoneNone
9tier_1habe.me1Dynadot, LLCNoneNone
10tier_2btpnav.com1191API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aristo-hag.com84Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_21496.rawlexi.com42GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
13tier_2americanlisted.com41ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
14tier_29nl.es16NoneNoneNone
15tier_2newre-conversions.clickmeter.com16REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
16tier_2trk.jometer.com16Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
17tier_2api.l5srv.net16GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
18tier_2melanthios-ana.com15Amazon Registrar, Inc.NS-1354.AWSDNS-41.ORGWhois Privacy Service
19tier_2click.expmediadirect.com15NoneNoneNone
20tier_2traff0121.com15NAMECHEAP INCHANS.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
21tier_2contentgate.cam14URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
22tier_20.contentgate.cam14URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
23tier_21.contentgate.cam13URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
24tier_2us.expand-backend.mindmatch.ai11NoneNoneNone
25tier_22.contentgate.cam10URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
26tier_23.contentgate.cam7URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
27tier_2trfktunnel.com7NoneNoneNone
28tier_2aliexpress.com7Alibaba Cloud Computing (Beijing) Co., Ltd.NS1.ALIBABADNS.COMNone
29tier_2v4.s.arclk.net4PSI-USA, Inc. dba Domain RobotA.NS14.NETNone
30tier_3irl.com75GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
31tier_3upward.careers16GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
32tier_3loyality-program.com15Amazon Registrar, Inc.NS-108.AWSDNS-13.COMWhois Privacy Service
33tier_3us.tideri.com12united domains AGNS.UDAG.DENone
34tier_3aliexpress.com_LOOP_17NoneNoneNone
35tier_3us.allthetopbananas.com6ENOM, INC.DANE.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
36tier_3cehappear.fun4Dynadot LLCAIDEN.NS.CLOUDFLARE.COMNone
37tier_33.contentgate.cam3URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
38tier_3ram21.proasdf.com3GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
39tier_32.contentgate.cam3URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
40tier_3neuvoo.com2MarkMonitor, Inc.NS-1302.AWSDNS-34.ORGTalent.com
41tier_3bing.com2NoneNoneNone
42tier_3amazonhvh.thejobnetwork.com2GoDaddy.com, LLCNS-1356.AWSDNS-41.ORGRealMatch
43tier_3chrismoneymaker.com2GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
44tier_3bestsecretflirt.com2GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
45tier_3wayfair.com2NoneNoneNone
46tier_3aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGNone
47tier_3americanlisted.com1ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
48tier_3us.mindmatch.ai1NoneNoneNone
49tier_3joinsmarty.com1GoDaddy Online Services Cayman Islands LTDDOM.NS.CLOUDFLARE.COMNone
50tier_3adzuna.com1123-Reg LimitedNS-1197.AWSDNS-21.ORGAdHunter
51tier_3filter.onwardclick.com1NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
52tier_3fanatics.com1MarkMonitor, Inc.A1-147.AKAM.NETFanatics Inc.
53tier_3encontextadvertising.com_LOOP_11NoneNoneNone
54tier_3hotlguyhere.com11API GmbHNS-1324.AWSDNS-37.ORGRegistrant of hotlguyhere.com
55tier_3nissanusa.com1MarkMonitor Inc.EDNS2.ULTRADNS.BIZNone
56tier_3careers.homedepot.com1CSC CORPORATE DOMAINS, INC.A1-27.AKAM.NETHome Depot Product Authority, LLC
57tier_3shopnsave.world_LOOP_11NoneNoneNone
58tier_31.contentgate.cam1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
59tier_3contentgate.cam1URL Solutions Inc.HEATHER.NS.CLOUDFLARE.COMGLOBAL DOMAIN PRIVACY SERVICES INC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
3206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_116nannan
4207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_116nannan
5104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
737.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_16nannan
8104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
9185.107.56.197RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_15nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2120nannan
11178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_38nannan
12198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nannan
1335.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_31240.61.209.35.bc.googleusercontent.comnan
1418.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_234ec2-18-235-67-128.compute-1.amazonaws.comnan
1554.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_230ec2-54-208-107-202.compute-1.amazonaws.comnan
1652.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-52-72-29-7.compute-1.amazonaws.comnan
1788.99.101.106Hohen NeuendorfBrandenburgAS24940 Hetzner Online GmbH16540Germanytier_222static.106.101.99.88.clients.your-server.denan
1834.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-34-197-176-2.compute-1.amazonaws.comnan
1967.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_216nannan
20198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_215nannan
2134.120.235.106Kansas CityMissouriAS15169 Google LLC64121United Statestier_211106.235.120.34.bc.googleusercontent.comTrue
2223.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-23-21-53-13.compute-1.amazonaws.comnan
2323.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-23-21-166-45.compute-1.amazonaws.comnan
24184.85.14.232NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_27a184-85-14-232.deploy.static.akamaitechnologies.comnan
2599.84.114.53NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_27server-99-84-114-53.ewr52.r.cloudfront.netnan
2654.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-54-197-247-190.compute-1.amazonaws.comnan
2754.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-54-235-205-204.compute-1.amazonaws.comnan
28209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_25nannan
29173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_24nannan
3067.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_316nannan
3134.192.40.54AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_315ec2-34-192-40-54.compute-1.amazonaws.comnan
3254.205.240.192AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_312ec2-54-205-240-192.compute-1.amazonaws.comnan
3335.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_312123.171.246.35.bc.googleusercontent.comnan
3467.207.81.229North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_310nannan
3552.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_39ec2-52-73-153-209.compute-1.amazonaws.comnan
36100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_39pool-100-37-135-2.nycmny.fios.verizon.netnan
37167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_39nannan
3864.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_38nannan
39178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_38nannan
4052.73.87.228AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_36ec2-52-73-87-228.compute-1.amazonaws.comnan
41167.172.139.120North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_36nannan
4252.203.36.44AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_36ec2-52-203-36-44.compute-1.amazonaws.comnan
43157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_35nannan
44162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_33nannan
45104.26.13.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
46104.26.12.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
47204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32a-0001.a-msedge.netTrue
48199.83.128.213Redwood CityCaliforniaAS19551 Incapsula Inc94065United Statestier_32199.83.128.213.ip.incapdns.netTrue
4992.205.4.117StrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_32ip-92-205-4-117.ip.secureserver.netnan
5088.80.185.92LondonEnglandAS63949 Linode, LLCEC1AUnited Kingdomtier_32li678-92.members.linode.comnan
5167.207.80.24North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
5223.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-41-189-99.deploy.static.akamaitechnologies.comnan
5334.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-34-197-176-2.compute-1.amazonaws.comnan
54161.35.60.200North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
5535.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_31240.61.209.35.bc.googleusercontent.comnan
5634.235.174.239AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-34-235-174-239.compute-1.amazonaws.comnan
57172.67.75.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
58172.67.210.5San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
59104.26.12.42San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website