Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01231163980352021-01-1737.48.65.151Safari
tierdomaincountregistrarname_serversorg
0tier_1bitenergy.org1Allearthdomains.com LLCNS1.COMMONMX.COMNone
1tier_1write.name1NoneNoneNone
2tier_1beactivedentist.com1enom1008, Inc.NS1.COMMONMX.COMNone
3tier_15ka.me1Dynadot, LLCNoneNone
4tier_19novels.net1! #1 Host Japan, Inc.NS1.DNSNUTS.COMThe Management Group II
5tier_13files.net1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158497154
6tier_1andisucirta.com1DYNADOT14 LLCNS1.COMMONMX.COMNone
7tier_1vikings.name1NoneNoneNone
8tier_1applique.me1GoDaddy.com, LLCNoneNone
9tier_1archives.name1NoneNoneNone
10tier_21496.wcitianka.com31GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
11tier_2americanlisted.com31ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
12tier_2click.appcast.io29101Domain GRS LtdNS-85.AWSDNS-10.COMNone
13tier_2dprtb.com271API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
14tier_25339.wcitianka.com27GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
15tier_2tr.trackingsys.tech27DonDominio (SCIP)NS1.DONDOMINIO.COMSoluciones Corporativas IP, c/o Whois Proxy
16tier_2get38.admedit.net27NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
17tier_2careerbliss.com12GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
18tier_2trk.careerbliss.com12GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
19tier_2open.app.jobrapido.com6Marcaria.com International, Inc.NS-CLOUD-D1.GOOGLEDOMAINS.COMGDPR Masked
20tier_3careerbliss.com17GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
21tier_3soft4update.findperfectplaces4download.work5NoneNoneNone
22tier_3installworking.findyourultimateplayersfirst.best4NoneNoneNone
23tier_3workingupdate.findyourultimateplayersfirst.best4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
24tier_3ready4maintain.findyourultimateplayersfirst.best4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
25tier_3upgradelive.findperfectplaces4download.work3NoneNoneNone
26tier_3update2new.thestablegreatupgrades.best3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
27tier_3checksoft.findyourultimateplayersfirst.best3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
28tier_3applytothisjob.com2GoDaddy.com, LLCNS-1499.AWSDNS-59.ORGJobDig
29tier_3google.com2MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_113nannan
1207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_111nannan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_18nannan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_18nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_15nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_14nannan
6185.107.56.200AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_12nannan
837.48.65.150SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_12nannan
9104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_12nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_258nannan
1135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_231240.61.209.35.bc.googleusercontent.comnan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_228nannan
1334.231.10.22Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_227ec2-34-231-10-22.compute-1.amazonaws.comnan
14137.74.180.226StrasbourgGrand EstAS16276 OVH SAS67000Francetier_227ip226.ip-137-74-180.eunan
15207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_317cbsmtp1.careerbliss.comnan
1634.194.75.233Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_216ec2-34-194-75-233.compute-1.amazonaws.comnan
173.211.178.164Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_213ec2-3-211-178-164.compute-1.amazonaws.comnan
18100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.netnan
19178.33.228.114RoubaixHauts-de-FranceAS16276 OVH SAS59051 CEDEX 1Francetier_26ns3021656.ip-178-33-228.eunan
2054.175.171.244Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_327ec2-54-175-171-244.compute-1.amazonaws.comnan
21207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_317cbsmtp1.careerbliss.comnan
22209.236.97.202MinneapolisMinnesotaAS13649 Flexential Colorado Corp.55440United Statestier_32nannan
23184.87.68.204NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a184-87-68-204.deploy.static.akamaitechnologies.comnan
24100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.netnan
2535.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_32123.171.246.35.bc.googleusercontent.comnan
2652.217.87.164Virginia BeachVirginiaAS16509 Amazon.com, Inc.23479United Statestier_31s3-1-w.amazonaws.comnan
27172.217.9.228CliftonNew JerseyAS15169 Google LLC07015United Statestier_31lga34s11-in-f4.1e100.netnan
2823.227.38.32OttawaOntarioAS13335 Cloudflare, Inc.K2PCanadatier_31myshopify.comTrue
29172.232.19.91NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a172-232-19-91.deploy.static.akamaitechnologies.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website