Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0121119285002020-10-1937.48.65.151Chrome
tierdomaincountregistrarname_serversorg
0tier_1sengoku-expo.net1Soldierofonedomains.com, LLCNS1.DNSNUTS.COMNone
1tier_1ok-ch.net1Domain Name Root, LLCNS1.DNSNUTS.COMThe Management Group II
2tier_1mirrorfile.net1NamePal.com #8021 Inc.NS1.DNSNUTS.COMNone
3tier_1juggler-peka.net1Domaincomesaround.com LLCNS1.DNSNUTS.COMNone
4tier_1gobuybuy.net1SearchNResQ Inc.NS1.DNSNUTS.COMNone
5tier_1aimeflv.net1DomainSprouts.com LLCNS1.DNSNUTS.COMThe Management Group II
6tier_1forexbaron.net1Top Level Domains LLCNS1.DNSNUTS.COMThe Management Group II
7tier_1videopremium.net1Domainsareforever.net LLCNS1.DNSNUTS.COMThe Management Group II
8tier_1ssknfusai.net1eNom443, IncorporatedNS1.DNSNUTS.COMNone
9tier_1femdomshots.net1Line Drive Domains, LLCNS1.DNSNUTS.COMThe Management Group II
10tier_2dprtb.com16GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
11tier_21496.wcitianka.com16UNIREGISTRAR CORPNS-1096.AWSDNS-09.ORGNone
12tier_2americanlisted.com11ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
13tier_2click.expmediadirect.com9NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
14tier_2btpnative.com9GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
15tier_2infopicked.com9NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
16tier_2toovolution.club8NAMECHEAP INCdemi.ns.cloudflare.comWhoisGuard, Inc.
17tier_2wolve.pro8DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
18tier_2somoto.g2afse.com7GoDaddy.com, LLCNS-1393.AWSDNS-46.ORGAditec Solutions, UAB
19tier_2usa.mnason-hec.com7Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
20tier_3moviefinder365.com7Amazon Registrar, Inc.NS-1271.AWSDNS-30.ORGWhois Privacy Service
21tier_3pestexterminator.com6GoDaddy.com, LLCNS-1521.AWSDNS-62.ORGDomains By Proxy, LLC
22tier_3americanlisted.com5ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
23tier_3us.search.yahoo.com5MarkMonitor, Inc.NS1.YAHOO.COMOath Inc.
24tier_3smartdeals.icu4NAMECHEAP INCNS-813.AWSDNS-37.NETWhoisGuard, Inc.
25tier_3us.tideri.com3united domains AGNS.UDAG.DENone
26tier_3shipt.com_LOOP_12NoneNoneNone
27tier_3careerbliss.com2GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
28tier_3toovolution.club2NAMECHEAP INCdemi.ns.cloudflare.comWhoisGuard, Inc.
29tier_3kvvfl.wolve.pro1DANESCO TRADING LTDAIDEN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
ipcityregionpostalcountry_nametiercounthostname
0207.244.67.216ManassasVirginia20108United Statestier_110nan
1207.244.67.215ManassasVirginia20108United Statestier_110nan
2207.244.67.214ManassasVirginia20108United Statestier_18nan
3207.244.67.218ManassasVirginia20108United Statestier_18nan
4185.107.56.60RotterdamSouth Holland3012Netherlandstier_16nan
537.48.65.150AmsterdamNorth Holland1012Netherlandstier_14nan
6185.107.56.58RotterdamSouth Holland3012Netherlandstier_12nan
7185.107.56.57RotterdamSouth Holland3012Netherlandstier_12nan
837.48.65.151AmsterdamNorth Holland1012Netherlandstier_11nan
937.48.65.148AmsterdamNorth Holland1012Netherlandstier_11nan
10209.15.13.136TorontoOntarioM5NCanadatier_225nan
11198.54.112.216San JoseCalifornia95103United Statestier_220nan
12173.192.101.24DallasTexas75270United Statestier_21518.65.c0ad.ip4.static.sl-reverse.com
13209.132.243.15Los AngelesCalifornia90009United Statestier_212nan
1435.209.61.240ChicagoIllinois60666United Statestier_35240.61.209.35.bc.googleusercontent.com
15198.134.116.30New York CityNew York10013United Statestier_29nan
16212.32.249.99SoestUtrecht3765Netherlandstier_27nan
1754.225.132.253Virginia BeachVirginia23471United Statestier_27ec2-54-225-132-253.compute-1.amazonaws.com
18108.168.193.185DallasTexas75270United Statestier_26b9.c1.a86c.ip4.static.sl-reverse.com
19176.9.117.45AltusriedBavaria87452Germanytier_24static.45.117.9.176.clients.your-server.de
20100.37.135.2New York CityNew York10004United Statestier_311pool-100-37-135-2.nycmny.fios.verizon.net
21116.202.19.155PuneMaharashtra411005Indiatier_37static.155.19.202.116.clients.your-server.de
22204.13.108.145RichardsonTexas75082United Statestier_36nan
2335.209.61.240ChicagoIllinois60666United Statestier_35240.61.209.35.bc.googleusercontent.com
2466.218.84.137Atlantic CityNew Jersey08404United Statestier_35ats1.l7.search.vip.bf1.yahoo.com
2594.102.49.124AmsterdamNorth Holland1012Netherlandstier_34no-reverse-dns-configured.com
2635.246.171.123Frankfurt am MainHesse60311Germanytier_33123.171.246.35.bc.googleusercontent.com
27207.38.44.116IrvineCalifornia92618United Statestier_32cbsmtp1.careerbliss.com
2852.54.3.79Virginia BeachVirginia23471United Statestier_31ec2-52-54-3-79.compute-1.amazonaws.com
2954.163.21.106Virginia BeachVirginia23471United Statestier_31ec2-54-163-21-106.compute-1.amazonaws.com

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website