Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01491508130102021-03-1564.32.8.68Android
tierdomaincountregistrarname_serversorg
0tier_1bugpoint.net1SNAPNAMES 42, LLCNS1.DNSNUTS.COMNone
1tier_1albumkings.net1Snoqulamiedomains.com LLCNS1.DNSNUTS.COMNone
2tier_1h-dougadb.net1SNAPNAMES 16, LLCNS1.DNSNUTS.COMNone
3tier_1fcmexpert.net1Baracuda Domains, LLCNS1.DNSNUTS.COMNone
4tier_1asb-sakray.net1Domain Name Root LLCNS1.DNSNUTS.COMNone
5tier_1divxgay.net1SNAPNAMES 49, LLCNS1.DNSNUTS.COMNone
6tier_1dconvert.net1SNAPNAMES 91, LLCNS1.DNSNUTS.COMNone
7tier_1ava-producao.net1SNAPNAMES 45, LLCNS1.DNSNUTS.COMNone
8tier_1dkca.net1Domain Name Origin, LLCNS1.DNSNUTS.COMNone
9tier_1genuinagente.net1Name Find Source LLCNS1.DNSNUTS.COMNone
10tier_2alfik-fik.com73Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
11tier_2track.vcdc.com58Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
12tier_2ads35.adtelligent.com48DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
13tier_2dsp35.adtelligent.com48DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
14tier_2aibm1.mysearch.space48NoneNoneNone
15tier_2externals-1953518744.us-east-1.elb.amazonaws.com48MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
16tier_2search.snjsearch.com48GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2search-checker.com48Name.com, Inc.BETH.NS.CLOUDFLARE.COMDomain Protection Services, Inc.
18tier_2m.onlineweb.mobi48GoDaddy.com, LLCNoneNone
19tier_2btpnav.com241API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
20tier_3bing.com48MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
21tier_3storystudio.sfgate.com12CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
22tier_3trktraf.club4NAMECHEAP INCdns1.registrar-servers.comWhoisGuard, Inc.
23tier_3win5.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
24tier_3squirt.org3NAMECHEAP INCNS5.DNSMADEEASY.COMWhoisGuard, Inc.
25tier_3robogarden.io3GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
26tier_3win3.trustedpush.com3NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
27tier_3m.placesiteb.xyz2Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
28tier_3win2.trustedpush.com2NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
29tier_3win6.trustedpush.com2NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_115nannan
164.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_115customer.sharktech.netnan
264.32.8.67Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_115customer.sharktech.netnan
3185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_113nannan
464.32.8.68Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_111customer.sharktech.netnan
5185.107.56.60RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_110nannan
664.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_17customer.sharktech.netnan
7185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_16nannan
8167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_258static.197.8.233.167.clients.your-server.denan
9209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_248static-42-202-205-209.24shells.netnan
10209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_248static-43-202-205-209.24shells.netnan
1135.162.164.74PortlandOregonAS16509 Amazon.com, Inc.97256United Statestier_248ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
1254.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23458United Statestier_246ec2-54-84-27-165.compute-1.amazonaws.comnan
1334.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23458United Statestier_244ec2-34-200-146-95.compute-1.amazonaws.comnan
14104.21.41.235San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_243nanTrue
15192.241.228.85San FranciscoCaliforniaAS14061 DigitalOcean, LLC94124United Statestier_228nannan
1613.225.230.57New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-230-57.jfk51.r.cloudfront.netnan
1750.16.173.246Virginia BeachVirginiaAS14618 Amazon.com, Inc.23458United Statestier_227ec2-50-16-173-246.compute-1.amazonaws.comnan
18204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_332nanTrue
1913.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_316nanTrue
2098.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_312nannan
21100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_38pool-100-37-135-2.nycmny.fios.verizon.netnan
22104.248.224.185North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_34nannan
23158.106.84.60TorontoOntarioAS23498 COGECODATAM5NCanadatier_33register.squirt.orgnan
24104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
25104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
2613.225.230.12New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-230-12.jfk51.r.cloudfront.netnan
2713.225.230.57New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-230-57.jfk51.r.cloudfront.netnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website