Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0201620002020-11-2464.32.8.68Chrome
tierdomaincountregistrarname_serversorg
0tier_1sarcastic.us1UdomainName.com LLCns2.dnsnuts.comNone
1tier_1televisionshow.us1UdomainName.com LLCns1.dnsnuts.comNone
2tier_1lookuppage.us1UdomainName.com LLCns2.dnsnuts.comNone
3tier_1pspr.us1UdomainName.com LLCns2.dnsnuts.comNone
4tier_2dprtb.com1GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
5tier_2sopho-kat.com1Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
6tier_2ww1.televisionshow.us1UdomainName.com LLCns1.dnsnuts.comNone
7tier_2c.pageprotect.net1GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
8tier_211168258.searchiqnet.com1GoDaddy.com, LLCNS57.DOMAINCONTROL.COMDomains By Proxy, LLC
9tier_2clickserve.dartsearch.net1MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
10tier_2ad.doubleclick.net1NoneNoneNone
11tier_2dbc.pathroutes.com1GoDaddy.com, LLCNS75.DOMAINCONTROL.COMDomains By Proxy, LLC
12tier_2track.vcdc.com1Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
13tier_2clk.rtpdn11.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_3irl.com1GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
15tier_3samsung.com1NoneNoneNone
16tier_3protects.s3.us-east-2.amazonaws.com1MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
17tier_3turbo-pdf.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
iphostnamecityregionorgpostalcountry_nametiercount
064.32.8.69customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_11
1207.244.67.214nanManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_11
237.48.65.150nanAmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11
3185.107.56.57nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_11
4209.132.243.15nanGrand RapidsMichiganAS7296 Alchemy Communications, Inc.49502United Statestier_23
5209.15.13.136nanTorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_21
652.205.210.89ec2-52-205-210-89.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_21
7199.59.242.153nanTampaFloridaAS395082 Bodis, LLC33609United Statestier_21
8172.217.10.142lga34s16-in-f14.1e100.netMountain ViewCaliforniaAS15169 Google LLC94043United Statestier_21
9172.217.3.102lga34s18-in-f6.1e100.netMountain ViewCaliforniaAS15169 Google LLC94043United Statestier_21
1094.130.185.237static.237.185.130.94.clients.your-server.deNürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_21
11173.239.53.32nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_21
1234.198.58.156ec2-34-198-58-156.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23450United Statestier_21
13198.134.116.30nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_21
14104.248.63.248nanNorth BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31
1523.38.172.65a23-38-172-65.deploy.static.akamaitechnologies.comNewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31
1652.219.96.88s3-r-w.us-east-2.amazonaws.comColumbusOhioAS16509 Amazon.com, Inc.43209United Statestier_31
17178.128.246.195nanAmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_31

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website