Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
026726910161222021-04-1737.48.65.149Chrome
tierdomaincountregistrarname_serversorg
0tier_1alqasab.org1Allworldnames.com LLCNS1.COMMONMX.COMNone
1tier_1fluder.co1Communigal Communication Ltdns2.commonmx.comNone
2tier_1anjani.co1Communigal Communication Ltdns2.commonmx.comNone
3tier_1eminents.co.in1Dynadot LLCns1.commonmx.comNone
4tier_1emonj.net1DYNADOT17 LLCNS1.COMMONMX.COMNone
5tier_13bitco.in1Dynadot LLCns1.commonmx.comNone
6tier_1earabgirls.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1data-management.co1Communigal Communication Ltdns1.commonmx.comNone
8tier_1drcswanson.com1GoDaddy.com, LLCNS1.COMMONMX.COMDomains By Proxy, LLC
9tier_152lu.co1Communigal Communication Ltdns2.commonmx.comNone
10tier_2btpnav.com1341API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aristo-hag.com101Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_21496.rawlexi.com42GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
13tier_2americanlisted.com39ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
14tier_2click.expmediadirect.com22NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
15tier_2traff0121.com21NAMECHEAP INCHANS.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
16tier_2contentgate.club21URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
17tier_20.contentgate.club21URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
18tier_21.contentgate.club20URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
19tier_22.contentgate.club18URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
20tier_2btpnative.com161API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
21tier_29nl.es15NoneNoneNone
22tier_2newre-conversions.clickmeter.com15REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
23tier_2trk.jometer.com15Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
24tier_2api.l5srv.net15GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
25tier_23.contentgate.club14URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
26tier_2trfktunnel.com14NAMECHEAP INCDAVE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
27tier_2aliexpress.com14Alibaba Cloud Computing (Beijing) Co., Ltd.NS1.ALIBABADNS.COMNone
28tier_2us.expand-backend.mindmatch.ai12NoneNoneNone
29tier_2infopicked.com12NAMECHEAP INCNS0.DNSMADEEASY.COMPrivacy service provided by Withheld for Privacy ehf
30tier_3irl.com94GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
31tier_3upward.careers15GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
32tier_3aliexpress.com_LOOP_114NoneNoneNone
33tier_3us.tideri.com11united domains AGNS.UDAG.DENone
34tier_3neuvoo.com5MarkMonitor, Inc.NS-1302.AWSDNS-34.ORGTalent.com
35tier_33.contentgate.club4URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
36tier_3us.allthetopbananas.com3ENOM, INC.DANE.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
37tier_3americanlisted.com3ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
38tier_3wolve.pro3DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
39tier_3chrismoneymaker.com3GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
40tier_3loyality-program.com3Amazon Registrar, Inc.NS-108.AWSDNS-13.COMWhois Privacy Service
41tier_3amazonhvh.thejobnetwork.com2GoDaddy.com, LLCNS-1356.AWSDNS-41.ORGRealMatch
42tier_3google.com_LOOP_12NoneNoneNone
43tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
44tier_32.contentgate.club2URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
45tier_3om.forgeofempires.com2INWX GmbH & Co. KGNS.INWX.DEREDACTED FOR PRIVACY
46tier_3weniix.com2NoneNoneNone
47tier_3cehappear.fun1DYNADOT LLCAIDEN.NS.CLOUDFLARE.COMNone
48tier_3promorepublic.com1Onlinenic IncLIA.NS.CLOUDFLARE.COMPromoRepublic Oy
49tier_3godaddy.com1GoDaddy.com, LLCA1-245.AKAM.NETGo Daddy Operating Company, LLC
50tier_3wix.com1GoDaddy.com, LLCDNS1.P03.NSONE.NETWix.com, LTD.
51tier_3fanatics.com1MarkMonitor, Inc.A1-147.AKAM.NETFanatics Inc.
52tier_3shop.diesel.com1BARBERO & Associates LtdNS3.OTB.NETREDACTED FOR PRIVACY
53tier_3storystudio.sfgate.com1CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
54tier_3rd.bizrate.com1MarkMonitor Inc.NS-1189.AWSDNS-20.ORGNone
55tier_3juju.com1Network Solutions, LLCNS-1111.AWSDNS-10.ORGNone
56tier_3cartageous.com1GoDaddy.com, LLCNS-1390.AWSDNS-45.ORGDomains By Proxy, LLC
57tier_3filter.onwardclick.com1NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
58tier_3careers.homedepot.com1CSC CORPORATE DOMAINS, INC.A1-27.AKAM.NETHome Depot Product Authority, LLC
59tier_31.contentgate.club1URL Solutions Inc.hans.ns.cloudflare.comGLOBAL DOMAIN PRIVACY SERVICES INC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_123nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_119nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
8185.107.56.199RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_15nannan
9185.107.56.198RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_15nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2151nannan
11178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_37nannan
12198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nannan
1335.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
1488.99.101.106Hohen NeuendorfBrandenburgAS24940 Hetzner Online GmbH16540Germanytier_235static.106.101.99.88.clients.your-server.denan
1534.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_231ec2-34-197-176-2.compute-1.amazonaws.comnan
1654.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_231ec2-54-208-107-202.compute-1.amazonaws.comnan
1752.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_228ec2-52-72-29-7.compute-1.amazonaws.comnan
1818.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_223ec2-18-235-67-128.compute-1.amazonaws.comnan
19198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_222nannan
20173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21718.65.c0ad.ip4.static.sl-reverse.comnan
2167.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_215nannan
2234.120.235.106Kansas CityMissouriAS15169 Google LLC64121United Statestier_212106.235.120.34.bc.googleusercontent.comTrue
2354.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-54-235-205-204.compute-1.amazonaws.comnan
24104.102.139.248EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_29a104-102-139-248.deploy.static.akamaitechnologies.comnan
2554.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-54-197-247-190.compute-1.amazonaws.comnan
2699.84.114.65NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_27server-99-84-114-65.ewr52.r.cloudfront.netnan
2723.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-23-21-166-45.compute-1.amazonaws.comnan
2823.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-23-21-53-13.compute-1.amazonaws.comnan
29184.85.14.232NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_25a184-85-14-232.deploy.static.akamaitechnologies.comnan
30167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_316nannan
31100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_316pool-100-37-135-2.nycmny.fios.verizon.netnan
3267.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_315nannan
3354.205.240.192AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_312ec2-54-205-240-192.compute-1.amazonaws.comnan
3435.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_311123.171.246.35.bc.googleusercontent.comnan
3567.207.80.24North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_310nannan
36157.245.84.7North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_310nannan
3752.73.87.228AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_38ec2-52-73-87-228.compute-1.amazonaws.comnan
38161.35.60.200North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_37nannan
39178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_37nannan
40157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_36nannan
4152.203.36.44AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_36ec2-52-203-36-44.compute-1.amazonaws.comnan
4252.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_36ec2-52-73-153-209.compute-1.amazonaws.comnan
4367.207.81.229North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_35nannan
4464.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_35nannan
45167.172.139.120North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
4635.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
4752.86.219.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-52-86-219-129.compute-1.amazonaws.comnan
4892.205.4.117StrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_33ip-92-205-4-117.ip.secureserver.netnan
4934.192.40.54AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-34-192-40-54.compute-1.amazonaws.comnan
50199.83.128.213Redwood CityCaliforniaAS19551 Incapsula Inc94065United Statestier_32199.83.128.213.ip.incapdns.netTrue
51162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
52104.26.12.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
5354.242.20.247AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-54-242-20-247.compute-1.amazonaws.comnan
54212.48.98.37HamburgHamburgAS8893 Artfiles New Media GmbH20038Germanytier_32nannan
55162.0.209.104San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_32premium170-1.web-hosting.comnan
5699.84.189.25WashingtonWashington, D.C.AS16509 Amazon.com, Inc.20045United Statestier_31server-99-84-189-25.iad89.r.cloudfront.netnan
57172.67.72.21San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
58172.67.75.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5923.1.196.29EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-1-196-29.deploy.static.akamaitechnologies.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website