Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0165172729002020-10-2364.32.8.68Android
tierdomaincountregistrarname_serversorg
0tier_1paladarhabana61.com1Compuglobalhypermega.com LLCNS1.DNSNUTS.COMNone
1tier_1indiancag.org1Betterthanaveragedomains.com LLCNS1.DNSNUTS.COMThe Management Group II
2tier_1fnanon.com1SNAPNAMES 76, LLCNS1.DNSNUTS.COMNone
3tier_1pick-bit.com1NamePal.com #8019, LLCNS1.DNSNUTS.COMNone
4tier_1pokeunlock.com1ThirdFloorDNS.com LLCNS1.DNSNUTS.COMNone
5tier_1xboxlivescore.com1Lucky Elephant Domains, LLCNS1.DNSNUTS.COMNone
6tier_1mospeen.com1Allworldnames.com LLCNS1.DNSNUTS.COMNone
7tier_1worktelnet.com1Mvpdomainnames.com LLCNS1.DNSNUTS.COMNone
8tier_1ice-app.net1OldTownDomains.com LLCNS1.DNSNUTS.COMNone
9tier_1babierus.com1NameSilo, LLCNS1.DNSNUTS.COMSee PrivacyGuardian.org
10tier_2track.tkbo.com72Key-Systems GmbHNS1.DNSRES.NETc/o whoisproxy.com
11tier_2get.popplunder.com48NoneNoneNone
12tier_2trustedpush.com43NoneNoneNone
13tier_2win1.trustedpush.com43NoneNoneNone
14tier_2win2.trustedpush.com39NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
15tier_2track.spicefriends.com32NoneNoneNone
16tier_2usa.hermes-vib.com29Amazon Registrar, Inc.NS-1049.AWSDNS-03.ORGWhois Privacy Service
17tier_2win3.trustedpush.com28NoneNoneNone
18tier_2usd.hermes-vib.com25Amazon Registrar, Inc.NS-1049.AWSDNS-03.ORGWhois Privacy Service
19tier_2usa.mnason-hec.com23Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
20tier_3chirrupedchivari.club32NAMECHEAP INCnorm.ns.cloudflare.comWhoisGuard, Inc.
21tier_3unatrophieduntranquillise.club19NoneNoneNone
22tier_3win4.trustedpush.com13NoneNoneNone
23tier_3win5.trustedpush.com13NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
24tier_3win3.trustedpush.com11NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
25tier_3win2.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
26tier_3stripchat.com3NoneNoneNone
27tier_3encryptalert.com3NoneNoneNone
28tier_3amazon.com2MarkMonitor, Inc.NS1.P31.DYNECT.NETAmazon Technologies, Inc.
29tier_3trustedpush.com2NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_134nan
1207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_122nan
2207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_119nan
3207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_118nan
464.32.8.67Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_14customer.sharktech.net
564.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_14customer.sharktech.net
637.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nan
7185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nan
864.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_12customer.sharktech.net
9185.107.56.60RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_11nan
1052.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_252ec2-52-205-210-89.compute-1.amazonaws.com
1134.199.107.160Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_251ec2-34-199-107-160.compute-1.amazonaws.com
1213.225.228.21Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_35server-13-225-228-21.jfk51.r.cloudfront.net
1334.199.180.187Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_249ec2-34-199-180-187.compute-1.amazonaws.com
1413.225.228.101Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_35server-13-225-228-101.jfk51.r.cloudfront.net
1554.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_247ec2-54-225-132-253.compute-1.amazonaws.com
1613.225.228.116Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_36server-13-225-228-116.jfk51.r.cloudfront.net
1713.225.228.15Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_33server-13-225-228-15.jfk51.r.cloudfront.net
1894.130.186.231NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_221static.231.186.130.94.clients.your-server.de
1994.130.185.237NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_216static.237.185.130.94.clients.your-server.de
20149.28.49.220New York CityNew YorkAS20473 Choopa, LLC10004United Statestier_332149.28.49.220.vultr.com
21100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_326pool-100-37-135-2.nycmny.fios.verizon.net
2245.32.198.135DallasTexasAS20473 Choopa, LLC75270United Statestier_31945.32.198.135.vultr.com
2313.225.228.116Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_36server-13-225-228-116.jfk51.r.cloudfront.net
2413.225.228.101Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_35server-13-225-228-101.jfk51.r.cloudfront.net
2513.225.228.21Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_35server-13-225-228-21.jfk51.r.cloudfront.net
26144.202.107.3Live OakCaliforniaAS20473 Choopa, LLC95953United Statestier_33144.202.107.3.vultr.com
2713.225.228.15Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_33server-13-225-228-15.jfk51.r.cloudfront.net
2813.225.224.25Atlantic CityNew JerseyAS16509 Amazon.com, Inc.08404United Statestier_32server-13-225-224-25.jfk51.r.cloudfront.net
29151.101.0.200MadridMadridAS54113 Fastly28001Spaintier_32nan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website