Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01651686621222021-04-0864.32.8.68Safari
tierdomaincountregistrarname_serversorg
0tier_1gaitametore.com1Blisternet, IncorporatedNS1.DNSNUTS.COMNone
1tier_1cupidonx.com1eNom375, IncorporatedNS1.DNSNUTS.COMNone
2tier_1brickerenterprise.com1NamePal.com #8011 Inc.NS1.DNSNUTS.COMNone
3tier_1fuge.it1Munpe Invest SLnNone
4tier_1antiilluminati.net1Hawthornedomains.com LLCNS1.DNSNUTS.COMNone
5tier_1beritatrendz.com1Nameselite, LLCNS1.DNSNUTS.COMNone
6tier_1bagustekno.net1Zone of Domains LLCNS1.DNSNUTS.COMNone
7tier_1cilipu.com1eNomSky, Inc.NS1.DNSNUTS.COMNone
8tier_1aptrk10.com1One Putt, Inc. (formerly:Z-Core, Inc.)NS1.DNSNUTS.COMNone
9tier_1dconvert.net1eNomFor, Inc.NS1.DNSNUTS.COMNone
10tier_2btpnav.com561API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_21496.rawlexi.com35GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
12tier_2americanlisted.com34ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
13tier_29nl.es34NoneNoneNone
14tier_2newre-conversions.clickmeter.com34REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
15tier_2trk.jometer.com34Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
16tier_2api.l5srv.net34GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2nizephoros-pom.com28Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
18tier_2click.expmediadirect.com18NoneNoneNone
19tier_2managerformula.com12NoneNoneNone
20tier_2track.vcdc.com10Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
21tier_2asufij.xyz10NoneNoneNone
22tier_2hureseyd.top9NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
23tier_2clk.rtpdn12.com7NoneNoneNone
24tier_2btpnative.com71API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
25tier_2infopicked.com6NoneNoneNone
26tier_2api.apptap.com6Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
27tier_2api.mplayit.com6Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
28tier_2redirect.viglink.com6Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
29tier_2link.sylikes.com6MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
30tier_3upward.careers34GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
31tier_3managerformula.com15NoneNoneNone
32tier_3s3.amazonaws.com13MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
33tier_3xzb.subeamy.pw10NoneNoneNone
34tier_3blockchain-com.email4NameSilo, LLCns1.selectel.orgSee PrivacyGuardian.org
35tier_3reebok.com4CSC CORPORATE DOMAINS, INC.NS1.NETNAMES.NETReebok International, Ltd.
36tier_3play.google.com3MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
37tier_3bing.com3NoneNoneNone
38tier_3check-your-profitzone.life2NoneNoneNone
39tier_3rd.bizrate.com2NoneNoneNone
40tier_3runnewest-bestextremelyfile.best2NoneNoneNone
41tier_3americanlisted.com1ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
42tier_3lastminute.com1MarkMonitor, Inc.NS-1042.AWSDNS-02.ORGBravonext S.A.
43tier_3apple.global-info.space1NoneNoneNone
44tier_3booking.com1NoneNoneNone
45tier_3wayfair.com1NoneNoneNone
iphostnamecityregionorgpostalcountry_nametiercountanycast
064.32.8.70customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_121nan
164.32.8.67customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_116nan
2185.107.56.60nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_114nan
364.32.8.69customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_111nan
464.32.8.68customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_110nan
5185.107.56.58nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_110nan
6185.107.56.59nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_18nan
7185.107.56.57nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_17nan
8209.15.13.136nanTorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_267nan
9198.54.112.216nanSan JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_236nan
1035.209.61.240240.61.209.35.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_31nan
1167.227.173.37nanLansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_234nan
1223.21.53.13ec2-23-21-53-13.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_221nan
1323.21.166.230ec2-23-21-166-230.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_218nan
14198.134.116.30nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_218nan
1554.197.247.190ec2-54-197-247-190.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_216nan
1654.235.205.204ec2-54-235-205-204.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213nan
17192.138.218.207rd.bizrate.comSeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_32nan
1899.84.114.17server-99-84-114-17.ewr52.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_210nan
19167.233.8.197static.197.8.233.167.clients.your-server.deNürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_210nan
2099.84.114.25server-99-84-114-25.ewr52.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_210nan
2134.197.176.2ec2-34-197-176-2.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29nan
2234.207.43.7ec2-34-207-43-7.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29nan
23185.233.2.13nanSaint PetersburgSt.-PetersburgAS48096 Enterprise Cloud Ltd.190000Russiatier_29nan
2499.84.114.65server-99-84-114-65.ewr52.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_28nan
25173.239.53.32nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_28nan
26173.192.101.2418.65.c0ad.ip4.static.sl-reverse.comDallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_27nan
2752.206.141.190ec2-52-206-141-190.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27nan
2867.227.172.40nanLansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_334nan
2923.38.167.202a23-38-167-202.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_38nan
3035.165.21.241ec2-35-165-21-241.us-west-2.compute.amazonaws.comBoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_37nan
3123.38.167.227a23-38-167-227.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_34nan
3223.44.210.223a23-44-210-223.deploy.static.akamaitechnologies.comEdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_34nan
3323.38.167.192a23-38-167-192.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_33nan
3452.88.215.122ec2-52-88-215-122.us-west-2.compute.amazonaws.comBoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_33nan
35172.217.165.142lax30s03-in-f14.1e100.netLos AngelesCaliforniaAS15169 Google LLC90009United Statestier_32nan
3652.217.88.230s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32nan
375.8.47.52nanHaarlemNorth HollandAS209813 Fast Content Delivery LTD2031Netherlandstier_32nan
3813.107.21.200nanRedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32True
3931.184.202.191nanHaarlemNorth HollandAS209813 Fast Content Delivery LTD2031Netherlandstier_32nan
40192.138.218.207rd.bizrate.comSeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_32nan
41100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32nan
4252.217.110.190s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32nan
4352.20.53.118ec2-52-20-53-118.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32nan
44204.79.197.200a-0001.a-msedge.netRedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31True
4552.217.89.198s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
4652.216.147.150s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
4752.216.99.61s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
48142.250.80.14lga34s33-in-f14.1e100.netNew York CityNew YorkAS15169 Google LLC10004United Statestier_31nan
4952.216.100.245s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
5052.217.79.126s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
5135.209.61.240240.61.209.35.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_31nan
5252.217.169.16s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
5352.217.13.166s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
54104.18.142.27nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
5552.216.16.155s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
5652.217.102.62s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
57104.21.78.145nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website