Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0292884002020-10-0864.32.8.68Android
tierdomaincountregistrarname_serversorg
0tier_1usakanalist.com1Free Spirit Domains, LLCNS1.DNSNUTS.COMNone
1tier_1we-are-gamers.com1The Domains LLCNS1.DNSNUTS.COMThe Management Group II
2tier_1nhahangthanbien.com1NamePal.com #8012 Inc.NS1.DNSNUTS.COMNone
3tier_1easybed.nl1EuroDNS S.A.ns1.dnsnuts.comNone
4tier_1msnboard.net1eNom457, IncorporatedNS1.DNSNUTS.COMNone
5tier_11kc-stare.net1AtlanticFriendNames.com LLCNS1.DNSNUTS.COMNone
6tier_1monroecountycommunitycreditunion.com1Sea Wasp, LLCNS1.DNSNUTS.COMSavvy Investments, LLC Privacy ID# 959006
7tier_1daohd.com1Domainstreetdirect.com LLCNS1.DNSNUTS.COMThe Management Group II
8tier_1wallsbase.net1eNom Corporate, Inc.NS1.DNSNUTS.COMThe Management Group II
9tier_1hqoboi.com1NamePal.com #8009 Inc.NS1.DNSNUTS.COMNone
10tier_2dprtb.com7GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
11tier_2get.popplunder.com7NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
12tier_2trustedpush.com7NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
13tier_2win1.trustedpush.com7NoneNoneNone
14tier_2win2.trustedpush.com7NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2win3.trustedpush.com7NoneNoneNone
16tier_2usd.mnason-hec.com6Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
17tier_2win4.trustedpush.com4NameCheap, Inc.NS-1142.AWSDNS-14.ORGNone
18tier_2usa.claudia-luc.com3Amazon Registrar, Inc.NS-1534.AWSDNS-63.ORGWhois Privacy Service
19tier_2trackyourmpg.com2UNIREGISTRAR CORPHUGH.NS.CLOUDFLARE.COMNone
20tier_3win4.trustedpush.com3NoneNoneNone
21tier_3gladmpath.xyz2Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
22tier_3win5.trustedpush.com2NoneNoneNone
23tier_3gaugecreate.club1NoneNoneNone
24tier_3win7.trustedpush.com1NoneNoneNone
25tier_3win6.trustedpush.com1NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_12nan
1207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_12nan
2207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_12nan
346.166.182.115AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
437.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
537.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
6207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_11nan
799.84.118.35NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-118-35.ewr52.r.cloudfront.net
899.84.118.87NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_212server-99-84-118-87.ewr52.r.cloudfront.net
9209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_27nan
1034.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_27ec2-34-199-180-187.compute-1.amazonaws.com
1152.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_25ec2-52-205-210-89.compute-1.amazonaws.com
1254.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_25ec2-54-225-132-253.compute-1.amazonaws.com
1399.84.118.101NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-118-101.ewr52.r.cloudfront.net
1499.84.118.103NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_24server-99-84-118-103.ewr52.r.cloudfront.net
15104.18.25.3Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_22nan
1691.195.240.136MunichBavariaAS47846 SEDO GmbH80331Germanytier_21nan
17100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_35pool-100-37-135-2.nycmny.fios.verizon.net
18104.18.82.149Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_32nan
19149.28.49.220New York CityNew YorkAS20473 Choopa, LLC10004United Statestier_31149.28.49.220.vultr.com
2099.84.118.101NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-118-101.ewr52.r.cloudfront.net
2199.84.118.35NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-118-35.ewr52.r.cloudfront.net

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website