Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0159157381002020-12-2137.48.65.151Chrome
tierdomaincountregistrarname_serversorg
0tier_1freemoneysystem.net1Interlakenames.com LLCNS1.DNSNUTS.COMNone
1tier_1animehentaitube.net1Heavydomains.net LLCNS1.DNSNUTS.COMNone
2tier_1jrpgreview.com1SNAPNAMES 42, LLCNS1.DNSNUTS.COMNone
3tier_1deadlysinx.net1Domains of Origin, LLCNS1.DNSNUTS.COMNone
4tier_1lordntaylor.com1Sea Wasp, LLCNS1.DNSNUTS.COMSavvy Investments, LLC Privacy ID# 937761
5tier_1juggler-peka.net1Domaincomesaround.com LLCNS1.DNSNUTS.COMNone
6tier_1crafthd.net1SNAPNAMES 42, LLCNS1.DNSNUTS.COMNone
7tier_1spimy.us1UdomainName.com LLCns2.dnsnuts.comNone
8tier_1itiraku.net1Free Drop Zone LLCNS1.DNSNUTS.COMNone
9tier_1dakmm.com1Private Domains, LLCNS1.DNSNUTS.COMNone
10tier_2track.vcdc.com33Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
11tier_2click.expmediadirect.com29NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
12tier_2clk.rtpdn12.com23NoneNoneNone
13tier_2euphe-gun.com18Amazon Registrar, Inc.NS-1325.AWSDNS-37.ORGWhois Privacy Service
14tier_2media-px.com13GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
15tier_2servedby.flashtalking.com13MESH DIGITAL LIMITEDNS1.P09.DYNECT.NETFlashtalking, Inc.
16tier_2build.mediapicker.com10GoDaddy.com, LLCRAQUEL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
17tier_2click.junmediadirect.com7NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
18tier_2btpnative.com51API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
19tier_2infopicked.com5NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
20tier_3fortunerain.info18GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
21tier_3socalhondadealers.com13DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
22tier_3turbo-pdf.com13NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
23tier_3casinoentity.info9GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
24tier_3track.vcdc.com8Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
25tier_3worldoftanks.ru3RU-CENTER-RUns1.wargaming.net.Wargaming.net Limited
26tier_3squirt.org2NAMECHEAP INCNS5.DNSMADEEASY.COMWhoisGuard, Inc.
27tier_3boot-upquick-theintenselyfile.best2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
28tier_3streamswiftcompletelypro.best2NamecheapDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
29tier_3boot-uprefined-thecompletelyfile.best2NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_119nannan
2207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_117nannan
3207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_111nannan
4185.107.56.58AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_16nannan
537.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
6185.107.56.60AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
7185.107.56.57AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
837.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nannan
937.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nannan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_229nannan
11173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_226nannan
12205.185.216.10DallasTexasAS20446 Highwinds Network Group, Inc.75201United Statestier_212map2.hwcdn.netTrue
13144.76.1.130NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_211static.130.1.76.144.clients.your-server.denan
1494.130.186.231NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_210static.231.186.130.94.clients.your-server.denan
1518.210.49.168Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_210ec2-18-210-49-168.compute-1.amazonaws.comnan
16209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_29nannan
1794.130.185.237NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_28static.237.185.130.94.clients.your-server.denan
18172.67.134.220San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_27nanTrue
1934.226.113.11Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_27ec2-34-226-113-11.compute-1.amazonaws.comnan
20178.128.246.195AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_313nannan
21172.67.185.52San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_310nanTrue
2275.101.207.6Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_310ec2-75-101-207-6.compute-1.amazonaws.comnan
23195.201.92.254NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_38static.254.92.201.195.clients.your-server.denan
2434.207.4.240Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_37ec2-34-207-4-240.compute-1.amazonaws.comnan
25104.31.95.162San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
26104.24.120.9San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
2735.174.35.73Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_36ec2-35-174-35-73.compute-1.amazonaws.comnan
2892.223.21.73LuxembourgLuxembourgAS199524 G-Core Labs S.A.L-1882Luxembourgtier_33ed-sl-b73.fe.core.pwnan
29158.106.84.60TorontoOntarioAS23498 COGECODATAM5NCanadatier_32www.squirtmail.comnan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website