Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01661757270282021-01-2137.48.65.151Android
tierdomaincountregistrarname_serversorg
0tier_1mcoo.me1Dynadot, LLCNoneNone
1tier_1cjiasuapp.me1GoDaddy.com, LLCNoneNone
2tier_1imagie.me1Dynadot, LLCNoneNone
3tier_1bbpress.me1Dynadot, LLCNoneNone
4tier_1maahi.me1GoDaddy.com, LLCNoneNone
5tier_1lich.me1GoDaddy.com, LLCNoneNone
6tier_1buyerbest.me1Dynadot, LLCNoneNone
7tier_1docx.me1Dynadot, LLCNoneNone
8tier_1gowebinar.me1Dynadot, LLCNoneNone
9tier_1balena.me1Dynadot, LLCNoneNone
10tier_21496.wcitianka.com103GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
11tier_2americanlisted.com98ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
12tier_2click.appcast.io80101Domain GRS LtdNS-85.AWSDNS-10.COMNone
13tier_2careerbliss.com49GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
14tier_2trk.careerbliss.com44GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
15tier_2click.appcast.io_LOOP_129NoneNoneNone
16tier_2open.app.jobrapido.com10Marcaria.com International, Inc.NS-CLOUD-D1.GOOGLEDOMAINS.COMGDPR Masked
17tier_2us.jobrapido.com10Marcaria.com International, Inc.NS-CLOUD-D1.GOOGLEDOMAINS.COMGDPR Masked
18tier_2alfik-fik.com9Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
19tier_2joblift.com8INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMNone
20tier_3careerbliss.com31GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
21tier_3google.com18MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
22tier_3linkedin.com7NoneNoneNone
23tier_3trk.careerbliss.com5GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
24tier_3job-openings.monster.com5CSC CORPORATE DOMAINS, INC.NS1.TMPW.NETMonster Worldwide, Inc.
25tier_3delightcmain.xyz5NoneNoneNone
26tier_3open.app.jobrapido.com_LOOP_15NoneNoneNone
27tier_3us.tideri.com4united domains AGNS.UDAG.DENone
28tier_3glassdoor.com4MarkMonitor, Inc.JILL.NS.CLOUDFLARE.COMGlassdoor, Inc.
29tier_3americanlisted.com4ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_121nannan
1207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nannan
2207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_116nannan
3206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
4207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_110nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_17nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
837.48.65.148SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_14nannan
9185.107.56.200AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_13nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_2103nannan
1135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_34240.61.209.35.bc.googleusercontent.comnan
12207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_336cbsmtp1.careerbliss.comnan
13100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_310pool-100-37-135-2.nycmny.fios.verizon.netnan
1434.194.75.233Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_242ec2-34-194-75-233.compute-1.amazonaws.comnan
153.211.178.164Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_238ec2-3-211-178-164.compute-1.amazonaws.comnan
16178.33.228.114RoubaixHauts-de-FranceAS16276 OVH SAS59051 CEDEX 1Francetier_210ns3021656.ip-178-33-228.eunan
1735.190.64.22Kansas CityMissouriAS15169 Google LLC64121United Statestier_2822.64.190.35.bc.googleusercontent.comTrue
1834.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23479United Statestier_27ec2-34-200-146-95.compute-1.amazonaws.comnan
1913.225.65.22NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_26server-13-225-65-22.ewr53.r.cloudfront.netnan
20207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_336cbsmtp1.careerbliss.comnan
21100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_310pool-100-37-135-2.nycmny.fios.verizon.netnan
22172.217.12.132Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_38lga34s19-in-f4.1e100.netnan
23104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
24172.217.10.4Mountain ViewCaliforniaAS15169 Google LLC94043United Statestier_35lga34s12-in-f4.1e100.netnan
2513.107.42.14RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_35nanTrue
2635.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_34123.171.246.35.bc.googleusercontent.comnan
2735.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_34240.61.209.35.bc.googleusercontent.comnan
28172.67.75.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
2913.225.210.34NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_33server-13-225-210-34.ewr50.r.cloudfront.netnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website