Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
07267185002020-10-0837.48.65.151Chrome
tierdomaincountregistrarname_serversorg
0tier_1trethovn.net1Domainstreetdirect.com LLCNS1.DNSNUTS.COMNone
1tier_1lordntaylor.com1Sea Wasp, LLCNS1.DNSNUTS.COMSavvy Investments, LLC Privacy ID# 937761
2tier_1akeremuna2018.com1Domain Secure LLCNS1.DNSNUTS.COMNone
3tier_1m-drug.com1Fetch Registrar, LLCNS1.DNSNUTS.COMNone
4tier_1hautephones.com1Domainsofcourse.com LLCNS1.DNSNUTS.COMNone
5tier_1medallionlearning.com1Private Domains, LLCNS1.DNSNUTS.COMNone
6tier_1eromini.com1Godomaingo.com LLCNS1.DNSNUTS.COMNone
7tier_1honyolar.com1NamePal.com #8024, LLCNS1.DNSNUTS.COMNone
8tier_1fileswill.com1MidWestDomains, LLCNS1.DNSNUTS.COMNone
9tier_1usthb.info1Domaincomesaround.com LLCNS1.DNSNUTS.COMThe Management Group II
10tier_2btpnative.com24GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
11tier_2infopicked.com23NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
12tier_2p274639.infopicked.com22NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
13tier_210.trackints.com14NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
14tier_2106.trackints.com8NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
15tier_2c.pageprotect.net3GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
16tier_211165151.searchiqnet.com2GoDaddy.com, LLCNS57.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2toovolution.club2NAMECHEAP INCdemi.ns.cloudflare.comWhoisGuard, Inc.
18tier_2usa.claudia-luc.com2Amazon Registrar, Inc.NS-1534.AWSDNS-63.ORGWhois Privacy Service
19tier_26102.xg4ken.com1GoDaddy.com, LLCDNS1.P02.NSONE.NETKenshoo TLD
20tier_3wix.com14GoDaddy.com, LLCNS1.P14.DYNECT.NETWix.com, LTD.
21tier_3pestexterminator.com8GoDaddy.com, LLCNS-1521.AWSDNS-62.ORGDomains By Proxy, LLC
22tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETNone
23tier_3linzess.com1Network Solutions, LLCHA1.MARKMONITOR.ZONENone
24tier_3wolve.pro1DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
25tier_3z98wg.wolve.pro1DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
26tier_3jmclaughlin.com1Network Solutions, LLCNS1.P17.DYNECT.NETNone
27tier_3p274639.infopicked.com1NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
28tier_3thenewfling.com1Amazon Registrar, Inc.NS-1085.AWSDNS-07.ORGWhois Privacy Service
29tier_3myfood.ltd1NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_18nan
1207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_17nan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_16nan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_14nan
437.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nan
537.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
637.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
746.166.182.116AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
846.166.182.114AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
946.166.182.111AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
10173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_3118.65.c0ad.ip4.static.sl-reverse.com
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_225nan
12108.168.193.185DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_222b9.c1.a86c.ip4.static.sl-reverse.com
13209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_27nan
1454.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_23ec2-54-225-132-253.compute-1.amazonaws.com
15185.170.102.1LondonEnglandAS45028 Barefruit Ltd.EC1AUnited Kingdomtier_22nan
16199.59.242.153TampaFloridaAS395082 Bodis, LLC33609United Statestier_22nan
1795.142.19.2New York CityNew YorkAS20645 PurePeak Ltd.10004United Statestier_21nan
18172.217.6.238MillbrookNew YorkAS15169 Google LLC12545United Statestier_21lga25s55-in-f14.1e100.net
19172.217.10.38MillbrookNew YorkAS15169 Google LLC12545United Statestier_21lga34s13-in-f6.1e100.net
20204.13.108.145RichardsonTexasAS35914 Armor Defense Inc75082United Statestier_38nan
21185.230.61.98San JoseCaliforniaAS58182 Wix.com Ltd.95119United Statestier_36nan
22185.230.61.179San JoseCaliforniaAS58182 Wix.com Ltd.95119United Statestier_35nan
23185.230.61.163San JoseCaliforniaAS58182 Wix.com Ltd.95119United Statestier_33nan
2423.41.189.63NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-63.deploy.static.akamaitechnologies.com
2513.225.229.15Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_31server-13-225-229-15.jfk51.r.cloudfront.net
2634.196.151.230Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_31ec2-34-196-151-230.compute-1.amazonaws.com
27100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_31pool-100-37-135-2.nycmny.fios.verizon.net
28151.101.1.124San FranciscoCaliforniaAS54113 Fastly94107United Statestier_31nan
29173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_3118.65.c0ad.ip4.static.sl-reverse.com

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website