Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0161423002020-11-2464.32.8.68Android
tierdomaincountregistrarname_serversorg
0tier_1sarcastic.us1UdomainName.com LLCns2.dnsnuts.comNone
1tier_1televisionshow.us1UdomainName.com LLCns1.dnsnuts.comNone
2tier_1lookuppage.us1UdomainName.com LLCns2.dnsnuts.comNone
3tier_1pspr.us1UdomainName.com LLCns2.dnsnuts.comNone
4tier_2sopho-kat.com3Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
5tier_2atnpx.com3GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
6tier_2track.vcdc.com2Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
7tier_2ww1.televisionshow.us1UdomainName.com LLCns1.dnsnuts.comNone
8tier_2c.pageprotect.net1GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
9tier_211168258.searchiqnet.com1GoDaddy.com, LLCNS57.DOMAINCONTROL.COMDomains By Proxy, LLC
10tier_2clickserve.dartsearch.net1MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
11tier_2ad.doubleclick.net1NoneNoneNone
12tier_2dbc.pathroutes.com1GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
13tier_2dprtb.com1GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
14tier_3kbb.com3CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
15tier_3samsung.com1NoneNoneNone
iphostnamecityregionorgpostalcountry_nametiercount
064.32.8.69customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_11
1207.244.67.214nanManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_11
237.48.65.150nanAmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11
3185.107.56.57nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_11
454.225.132.253ec2-54-225-132-253.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_23
5209.132.243.15nanGrand RapidsMichiganAS7296 Alchemy Communications, Inc.49502United Statestier_23
6104.26.11.53nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_22
7144.76.1.130static.130.1.76.144.clients.your-server.deNürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_21
8199.59.242.153nanTampaFloridaAS395082 Bodis, LLC33609United Statestier_21
9172.217.10.142lga34s16-in-f14.1e100.netMountain ViewCaliforniaAS15169 Google LLC94043United Statestier_21
10142.250.64.102lga34s31-in-f6.1e100.netWestburyNew YorkAS15169 Google LLC11590United Statestier_21
11209.15.13.136nanTorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_21
1294.130.186.231static.231.186.130.94.clients.your-server.deNürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_21
13104.26.10.53nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_21
1423.44.209.107a23-44-209-107.deploy.static.akamaitechnologies.comEdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_33
1523.38.172.65a23-38-172-65.deploy.static.akamaitechnologies.comNewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website