Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
07575146002020-11-1864.32.8.68Chrome
tierdomaincountregistrarname_serversorg
0tier_1kakashi-stresser.com1Rare Gem Domains LLCNS1.DNSNUTS.COMNone
1tier_1freevstorrent.info1Domainhysteria.com LLCNS1.DNSNUTS.COM['The Management Group II', 'Statutory Masking Enabled']
2tier_1dqmj3.net1Domainsofcourse.com LLCNS1.DNSNUTS.COMThe Management Group II
3tier_1learn-turkish-ar2.com1Meganames LLCNS1.DNSNUTS.COMNone
4tier_172mn.com1JARHEADDOMAINS.COM, LLCNS1.DNSNUTS.COMNone
5tier_1dallahds.com1Domain Name Origin, LLCNS1.DNSNUTS.COMThe Management Group II
6tier_1betarchon.com1Gunga Galunga CorporationNS1.DNSNUTS.COMNone
7tier_1hqoboi.com1NamePal.com #8009 Inc.NS1.DNSNUTS.COMNone
8tier_1superposts.info1Adomainofyourown.com LLCNS1.DNSNUTS.COMStatutory Masking Enabled
9tier_1health-lifestyles.net1MidWest Domains LLCNS1.DNSNUTS.COMThe Management Group II
10tier_2click.expmediadirect.com6NoneNoneNone
11tier_24d3o4.rdtk.io6GoDaddy.com, LLCNS-239.AWSDNS-29.COMNone
12tier_2shiftexten.com6GoDaddy.com, LLCNS65.DOMAINCONTROL.COMDomains By Proxy, LLC
13tier_2clk.rtpdn11.com6NoneNoneNone
14tier_2track.vcdc.com6Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
15tier_2rqhere2.com5NoneNoneNone
16tier_2click.junmediadirect.com4NoneNoneNone
17tier_2traff8.biz4NoneNoneNone
18tier_2starcontent.cam4NoneNoneNone
19tier_20.starcontent.cam4NoneNoneNone
20tier_3funsafetab.com2GoDaddy.com, LLCNS69.DOMAINCONTROL.COMDomains By Proxy, LLC
21tier_3get.streamssitesearch.com2GoDaddy.com, LLCISLA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
22tier_3turbo-pdf.com2NoneNoneNone
23tier_3medianewpage.com2GoDaddy.com, LLCNS49.DOMAINCONTROL.COMDomains By Proxy, LLC
24tier_3chrome.google.com2MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
25tier_32.starcontent.cam1NoneNoneNone
26tier_3blog.sfchronicle.com1CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
27tier_3tco20.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
28tier_3amazonhvh.thejobnetwork.com1GoDaddy.com, LLCNS-1356.AWSDNS-41.ORGRealMatch
29tier_3us.sercanto.com1OVH, SASDNS20.OVH.NETWickedin s.r.l.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_18nan
1207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_14nan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_13nan
3207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_13nan
4185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nan
5185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_11nan
6178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nan
7108.59.81.209Council BluffsIowaAS15169 Google LLC51502United Statestier_34209.81.59.108.bc.googleusercontent.com
8198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_27nan
9173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_27nan
1023.81.176.198San FranciscoCaliforniaAS7203 Leaseweb USA, Inc.94103United Statestier_26nan
11195.201.207.27BerlinBerlinAS24940 Hetzner Online GmbH10178Germanytier_26static.27.207.201.195.clients.your-server.de
12167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_25nan
13198.134.116.18New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_24nan
1452.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_24ec2-52-205-210-89.compute-1.amazonaws.com
15209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_24nan
16108.59.81.209Council BluffsIowaAS15169 Google LLC51502United Statestier_34209.81.59.108.bc.googleusercontent.com
17178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nan
18178.128.246.195AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nan
19172.67.158.33San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nan
2098.129.228.57BrookhavenMississippiAS33070 Rackspace Hosting39601United Statestier_31nan
21162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_31nan
22199.83.128.213Redwood CityCaliforniaAS19551 Incapsula Inc94065United Statestier_31199.83.128.213.ip.incapdns.net
23172.217.11.46New York CityNew YorkAS15169 Google LLC10004United Statestier_31lga25s61-in-f14.1e100.net
24104.28.31.251San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nan
2534.90.160.43GroningenGroningenAS15169 Google LLC9711Netherlandstier_3143.160.90.34.bc.googleusercontent.com

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website