Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0139144584002021-01-0137.48.65.151Android
tierdomaincountregistrarname_serversorg
0tier_1lawichhoneybeeco.com1OldWorldAliases.com LLCNS1.DNSNUTS.COMNone
1tier_1flearning.net1Wide Left Domains LLCNS1.DNSNUTS.COMNone
2tier_1myhit.tv1Domain Name Root LLCNS1.DNSNUTS.COMNone
3tier_1fudgebananaswirl.com1Name Connection Spot LLCNS1.DNSNUTS.COMNone
4tier_1az-khaos.com1EUTurbo.com LLCNS1.DNSNUTS.COMNone
5tier_1qsanguosha.org1BullRunDomains.com LLCNS1.DNSNUTS.COMThe Management Group II
6tier_118land.net1DuckbilledDomains.com LLCNS1.DNSNUTS.COMNone
7tier_1aellaabroad.com1SNAPNAMES 35, LLCNS1.DNSNUTS.COMNone
8tier_1dailymastro.com1Veritas Domains, LLCNS1.DNSNUTS.COMNone
9tier_1freecric.net1Allworldnames.com LLCNS1.DNSNUTS.COMNone
10tier_2track.vcdc.com49Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
11tier_2bradamante-per.com48Amazon Registrar, Inc.NS-1026.AWSDNS-00.ORGWhois Privacy Service
12tier_2get.popplunder.com48NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
13tier_2trustedpush.com45NoneNoneNone
14tier_2win1.trustedpush.com43NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2win2.trustedpush.com29NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
16tier_2alfik-fik.com17Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
17tier_2win3.trustedpush.com16NoneNoneNone
18tier_2click.expmediadirect.com14NoneNoneNone
19tier_2rtbstream.com11GoDaddy.com, LLCNS1.DNSIMPLE.COMBidtellect, Inc
20tier_3win2.trustedpush.com14NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
21tier_3win3.trustedpush.com13NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
22tier_3win4.trustedpush.com10NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
23tier_3delightcmain.xyz8Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
24tier_3blog.sfgate.com7CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
25tier_3track.vcdc.com7Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
26tier_3win5.trustedpush.com6NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
27tier_3searchfrequently.com6GoDaddy.com, LLCNEIL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
28tier_3findoffers.co5Key-Systems GmbHns4.monikerdns.netMoniker Privacy Services
29tier_3a.upbeatcboulevard.xyz4Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_124nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_123nannan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_117nannan
3207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_110nannan
437.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
5185.107.56.57AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_15nannan
663.143.32.90DallasTexasAS46475 Limestone Networks, Inc.75202United Statestier_1290-32-143-63.static.reverse.lstn.netnan
7185.107.56.60AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_12nannan
837.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nannan
963.143.32.89DallasTexasAS46475 Limestone Networks, Inc.75202United Statestier_1189-32-143-63.static.reverse.lstn.netnan
1013.225.62.7NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_38server-13-225-62-7.ewr53.r.cloudfront.netnan
1134.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_248ec2-34-199-180-187.compute-1.amazonaws.comnan
1234.226.113.11Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_234ec2-34-226-113-11.compute-1.amazonaws.comnan
1334.202.98.117Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_231ec2-34-202-98-117.compute-1.amazonaws.comnan
1413.225.62.54NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_34server-13-225-62-54.ewr53.r.cloudfront.netnan
1513.225.62.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_36server-13-225-62-107.ewr53.r.cloudfront.netnan
1613.225.62.25NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_222server-13-225-62-25.ewr53.r.cloudfront.netnan
17209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_219nannan
1894.130.185.237NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_217static.237.185.130.94.clients.your-server.denan
19198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_214nannan
20100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_330pool-100-37-135-2.nycmny.fios.verizon.netnan
2113.225.62.7NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_38server-13-225-62-7.ewr53.r.cloudfront.netnan
22151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_37nanTrue
23195.201.92.254NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_36static.254.92.201.195.clients.your-server.denan
2413.225.62.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_36server-13-225-62-107.ewr53.r.cloudfront.netnan
2518.190.1.57ColumbusOhioAS16509 Amazon.com, Inc.43221United Statestier_35ec2-18-190-1-57.us-east-2.compute.amazonaws.comnan
26104.31.81.30San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
27104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
2813.225.62.54NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_34server-13-225-62-54.ewr53.r.cloudfront.netnan
29192.243.59.20WashingtonWashington, D.C.AS39572 DataWeb Global Group B.V.20045United Statestier_34nannan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website