Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02722758630212021-04-1837.48.65.149Iphone
tierdomaincountregistrarname_serversorg
0tier_1arrecharge.in1Dynadot LLCns1.commonmx.comNone
1tier_1anhdep.pro1DYNADOT LLCNS1.COMMONMX.COMNone
2tier_1dapool.me1Dynadot, LLCNoneNone
3tier_1kuniv.in1Dynadot LLCns1.commonmx.comNone
4tier_1flinzo.com1Dynadot5 LLCNS1.COMMONMX.COMNone
5tier_1boost.asia1Dynadot, LLCNS1.COMMONMX.COMNone
6tier_1divyabhasakr.co.in1Dynadot LLCns1.commonmx.comNone
7tier_1fujin.in1Dynadot LLCns1.commonmx.comNone
8tier_1emonj.net1Dynadot17 LLCNS1.COMMONMX.COMNone
9tier_1k18.me1GoDaddy.com, LLCNoneNone
10tier_2aristo-hag.com90Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2btpnav.com821API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2click.expmediadirect.com43NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
13tier_2atnpx.com40GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
14tier_2api.quotes.com30Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
15tier_2changeslots.com30Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
16tier_2clk.rtpdn12.com15NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
17tier_2exporimy.com14GoDaddy.com, LLCNS-1145.AWSDNS-15.ORGDomains By Proxy, LLC
18tier_2sorrectionki.space14NoneNoneNone
19tier_2security-rd.com12NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
20tier_2melanthios-ana.com8Amazon Registrar, Inc.NS-1354.AWSDNS-41.ORGWhois Privacy Service
21tier_2rqhere2.com8NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
22tier_2apptime.xyz7NAMECHEAP INCPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
23tier_263086.click.validclick.net6Safenames LtdNS1.FULLMAILBOX.COMNone
24tier_2xml.onwardclick.com5NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
25tier_2v4.s.arclk.net5PSI-USA, Inc. dba Domain RobotA.NS14.NETNone
26tier_2nizephoros-pom.com5Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
27tier_262994.click.validclick.net4Safenames LtdNS1.FULLMAILBOX.COMNone
28tier_2rd.bizrate.com4MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
29tier_2rd.connexity.net4NoneNoneNone
30tier_3bestappland.me34NAMECHEAP INCNoneNone
31tier_3theconnectvpn.com30DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
32tier_3kbb.com27CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
33tier_3storystudio.sfgate.com17CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
34tier_3irl.com14GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
35tier_3robogarden.io13GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
36tier_3java.limitedtopoffers.com81&1 IONOS SERORY.NS.CLOUDFLARE.COM1&1 Internet Inc
37tier_3tackis.xyz8NAMECHEAP INCPETE.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
38tier_3chrismoneymaker.com5GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
39tier_3gramp.xyz5NAMECHEAP INCDAVID.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
40tier_3ram21.proasdf.com3GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
41tier_3filter.onwardclick.com3NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
42tier_3beyourxfriend.com3GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
43tier_3vpn1aprotectplus.com3Internet Domain Service BS Corp.SETH.NS.CLOUDFLARE.COMWhois Privacy Corp.
44tier_3thelastpicture.show_LOOP_12NoneNoneNone
45tier_3weniix.com2NameCheap, Inc.DNS1.NAMECHEAPHOSTING.COMNone
46tier_3apple.com2CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
47tier_3rpa21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
48tier_3booking.com_LOOP_11NoneNoneNone
49tier_3ads.midwayusa.com1GoDaddy.com, LLCNS-1486.AWSDNS-57.ORGMidwayUSA
50tier_3stocks.etoro.com1DomainTheNet.comEUR5.AKAM.NET******
51tier_3wayfair.com1MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
52tier_3noom.com1GoDaddy.com, LLCABBY.NS.CLOUDFLARE.COMWorkSmart Labs, Inc.
53tier_3opticsplanet.com1GoDaddy.com, LLCNS1.ECENTRIA.COMECENTRIA IPH, LLC
54tier_3fanatics.com1MarkMonitor Inc.A1-147.AKAM.NETNone
55tier_3bulley.shop1NoneNoneNone
56tier_3neuvoo.com1NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
2207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
3207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
8185.107.56.199RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_15nannan
937.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_285nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_243nannan
1254.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_231ec2-54-208-107-202.compute-1.amazonaws.comnan
1334.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_230ec2-34-197-176-2.compute-1.amazonaws.comnan
145.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_230nannan
1534.207.32.33AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_230ec2-34-207-32-33.compute-1.amazonaws.comnan
1618.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_224ec2-18-235-67-128.compute-1.amazonaws.comnan
17104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_222nanTrue
18173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_33nannan
1952.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_219ec2-52-72-29-7.compute-1.amazonaws.comnan
20204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_217204.44.79.214.static.quadranet.comnan
2134.202.14.39AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_214ec2-34-202-14-39.compute-1.amazonaws.comnan
22172.67.74.77San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_210nanTrue
23104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_28nanTrue
24167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_28nannan
2534.234.154.208AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-34-234-154-208.compute-1.amazonaws.comnan
263.85.252.251AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-3-85-252-251.compute-1.amazonaws.comnan
27209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_26nannan
28192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_25rd.bizrate.comnan
2934.231.10.22AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-34-231-10-22.compute-1.amazonaws.comnan
30142.93.4.215North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_334nannan
3123.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_327a23-44-217-143.deploy.static.akamaitechnologies.comnan
32151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_317nanTrue
33104.21.91.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_317nanTrue
34172.67.181.234San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313nanTrue
35172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311nanTrue
3692.205.4.117StrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_35ip-92-205-4-117.ip.secureserver.netnan
37162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_35nannan
3852.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_35ec2-52-73-153-209.compute-1.amazonaws.comnan
39104.21.65.93San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
40104.21.28.174San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
41172.67.146.238San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
42100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_33pool-100-37-135-2.nycmny.fios.verizon.netnan
43173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_33nannan
44172.67.189.184San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
45104.21.92.190San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
4645.33.8.244RichardsonTexasAS63949 Linode, LLC75080United Statestier_33li962-244.members.linode.comnan
47104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
48162.0.209.104San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_32premium170-1.web-hosting.comnan
4923.38.172.250NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-38-172-250.deploy.static.akamaitechnologies.comnan
5052.73.87.228AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-52-73-87-228.compute-1.amazonaws.comnan
51167.172.139.120North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
52172.67.197.33San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
53104.21.63.48San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
54157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
55161.35.60.200North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
56104.102.136.83EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a104-102-136-83.deploy.static.akamaitechnologies.comnan
5723.51.164.175PhiladelphiaPennsylvaniaAS16625 Akamai Technologies, Inc.19099United Statestier_31a23-51-164-175.deploy.static.akamaitechnologies.comnan
58184.29.132.211EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a184-29-132-211.deploy.static.akamaitechnologies.comnan
59104.17.0.108San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website