Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02382439360262021-04-1937.48.65.149Safari
tierdomaincountregistrarname_serversorg
0tier_1moniker.name1NoneNoneNone
1tier_1arrecharge.in1Dynadot LLCns1.commonmx.comNone
2tier_1phimm.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1bomber22.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1anhdep.pro1DYNADOT LLCNS1.COMMONMX.COMNone
5tier_1nijigenmarket.net1eNom463, IncorporatedNS1.COMMONMX.COMNone
6tier_1mymp3song.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1dapool.me1Dynadot, LLCNoneNone
8tier_1flinzo.com1Dynadot5 LLCNS1.COMMONMX.COMNone
9tier_1boost.asia1Dynadot, LLCNS1.COMMONMX.COMNone
10tier_2btpnav.com1261API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_2aristo-hag.com58Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
12tier_2nizephoros-pom.com56Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
13tier_21496.rawlexi.com42GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
14tier_2americanlisted.com41ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_2btpnative.com281API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
16tier_2infopicked.com27NAMECHEAP INCNS0.DNSMADEEASY.COMPrivacy service provided by Withheld for Privacy ehf
17tier_29nl.es24NoneNoneNone
18tier_2newre-conversions.clickmeter.com24REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
19tier_2trk.jometer.com24Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
20tier_2api.l5srv.net24GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
21tier_2managerformula.com19NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
22tier_2click.expmediadirect.com16NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
23tier_2hureseyd.top10NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
24tier_2rtbstream.com71API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
25tier_2clk.rtpdn12.com6NoneNoneNone
26tier_2rqhere2.com6NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
27tier_2mega.affiliate-dash.com5NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
28tier_2blockchain-com.email4NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
29tier_2ads35.adtelligent.com3DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
30tier_3irl.com46GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
31tier_3managerformula.com37NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
32tier_3upward.careers24GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
33tier_3s3.amazonaws.com19MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
34tier_3us.tideri.com13united domains AGNS.UDAG.DENone
35tier_3blockchain-com.email6NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
36tier_3runnewest-bestextremelyfile.best5NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
37tier_3medicreed.club4NAMECHEAP INCmolly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
38tier_3tripleprofit-zone.life3NoneNoneNone
39tier_3bing.com3MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
40tier_3chrismoneymaker.com3GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
41tier_3click.appcast.io1101Domain GRS LtdNS-85.AWSDNS-10.COMNone
42tier_3americanlisted.com1ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
43tier_3play.google.com1NoneNoneNone
44tier_3aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
45tier_3etoro.com1DomainTheNet.comEUR5.AKAM.NET******
46tier_3us.jobtome.com1GoDaddy.com, LLCCHRIS.NS.CLOUDFLARE.COMJobtome Internantional SA
47tier_3orthofeet.com1Network Solutions, LLCNS27.WORLDNIC.COMORTHOFEET INC.
48tier_3amazonhvh.thejobnetwork.com1GoDaddy.com, LLCNS-1356.AWSDNS-41.ORGRealMatch
49tier_3storystudio.sfgate.com1CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
50tier_3adzuna.com1123-Reg LimitedNS-1197.AWSDNS-21.ORGAdHunter
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
3207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_119nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
8185.107.56.197RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
982.192.82.226AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2161nannan
11198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nannan
1235.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_241240.61.209.35.bc.googleusercontent.comnan
1352.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_230ec2-52-72-29-7.compute-1.amazonaws.comnan
1454.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_230ec2-54-208-107-202.compute-1.amazonaws.comnan
1534.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_229ec2-34-197-176-2.compute-1.amazonaws.comnan
16173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_22818.65.c0ad.ip4.static.sl-reverse.comnan
1718.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_225ec2-18-235-67-128.compute-1.amazonaws.comnan
1867.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_224nannan
19198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_216nannan
2054.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213ec2-54-197-247-190.compute-1.amazonaws.comnan
2123.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213ec2-23-21-53-13.compute-1.amazonaws.comnan
2223.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_211ec2-23-21-166-45.compute-1.amazonaws.comnan
2354.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_211ec2-54-235-205-204.compute-1.amazonaws.comnan
2423.38.167.227PhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_320a23-38-167-227.deploy.static.akamaitechnologies.comnan
25185.233.2.13Saint PetersburgSt.-PetersburgAS48096 Enterprise Cloud Ltd.190000Russiatier_210nannan
2699.84.114.53NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_29server-99-84-114-53.ewr52.r.cloudfront.netnan
2799.84.114.25NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_29server-99-84-114-25.ewr52.r.cloudfront.netnan
2823.38.167.202PhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_317a23-38-167-202.deploy.static.akamaitechnologies.comnan
29173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_26nannan
3067.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_324nannan
3123.38.167.227PhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_320a23-38-167-227.deploy.static.akamaitechnologies.comnan
3223.38.167.202PhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_317a23-38-167-202.deploy.static.akamaitechnologies.comnan
3335.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_313123.171.246.35.bc.googleusercontent.comnan
34161.35.60.200North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_37nannan
35167.172.136.193North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_36nannan
3652.20.53.118AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_35ec2-52-20-53-118.compute-1.amazonaws.comnan
375.8.47.52HaarlemNorth HollandAS209813 Fast Content Delivery LTD2031Netherlandstier_34nanTrue
3852.203.36.44AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34ec2-52-203-36-44.compute-1.amazonaws.comnan
3967.207.81.229North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_34nannan
4067.207.80.24North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_34nannan
4152.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34ec2-52-73-153-209.compute-1.amazonaws.comnan
4231.184.202.185HaarlemNorth HollandAS209813 Fast Content Delivery LTD2031Netherlandstier_33nanTrue
4364.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
44204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_33a-0001.a-msedge.netTrue
45104.21.68.134San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
4692.205.4.117StrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_33ip-92-205-4-117.ip.secureserver.netnan
4754.205.240.192AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-54-205-240-192.compute-1.amazonaws.comnan
4852.73.87.228AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-52-73-87-228.compute-1.amazonaws.comnan
49157.245.242.152North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nannan
50157.245.84.7North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
5152.217.94.206AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5252.216.106.134AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5352.217.64.246AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5452.216.178.237AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5552.216.22.45AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5652.44.140.30AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-52-44-140-30.compute-1.amazonaws.comnan
57100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.netnan
583.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-3-234-0-165.compute-1.amazonaws.comnan
5952.217.194.192AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website