Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01371464830172021-04-0964.32.8.68Chrome
tierdomaincountregistrarname_serversorg
0tier_1ciliguai.com1eNom437, IncorporatedNS1.DNSNUTS.COMThe Management Group II
1tier_19ref.com1Lionshare Domains, LLCNS1.DNSNUTS.COMThe Management Group II
2tier_19novels.net1! #1 Host Japan, Inc.NS1.DNSNUTS.COMThe Management Group II
3tier_1chastnoevideo.net1eNomEU, Inc.NS1.DNSNUTS.COMNone
4tier_1cuocsong365.net1Flancrestdomains.com LLCNS1.DNSNUTS.COMNone
5tier_1elektrononline.net1Blue Angel Domains LLCNS1.DNSNUTS.COMNone
6tier_1aayaamlabs.com1enom666, Inc.NS1.DNSNUTS.COMNone
7tier_1cheapvba.com1Adomainofyourown.com LLCNS1.DNSNUTS.COMNone
8tier_1aptrk10.com1One Putt, Inc. (formerly:Z-Core, Inc.)NS1.DNSNUTS.COMNone
9tier_1divxgay.net1eNom427, IncorporatedNS1.DNSNUTS.COMNone
10tier_2api.apptap.com22Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
11tier_2redirect.viglink.com22Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
12tier_2link.sylikes.com22MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
13tier_2aristo-hag.com20Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
14tier_2rd.bizrate.com19NoneNoneNone
15tier_2track.vcdc.com17Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
16tier_2rd.connexity.net17NoneNoneNone
17tier_2click.expmediadirect.com13NoneNoneNone
18tier_2api.mplayit.com12Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
19tier_2clk.rtpdn12.com11NoneNoneNone
20tier_2ads35.adtelligent.com11DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
21tier_2dsp35.adtelligent.com11DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
22tier_2externals-1953518744.us-east-1.elb.amazonaws.com11MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
23tier_2search.snjsearch.com11GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
24tier_2lulus.com10GoDaddy.com, LLCNS-1116.AWSDNS-11.ORGDomains By Proxy, LLC
25tier_2btpnav.com101API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
26tier_2infopicked.com9NoneNoneNone
27tier_2aldb1.mysearch.space9NoneNoneNone
28tier_2btpnative.com81API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
29tier_2nizephoros-pom.com6Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGNone
30tier_3lulus.com_LOOP_110NoneNoneNone
31tier_3bing.com10MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
32tier_3rd.bizrate.com8NoneNoneNone
33tier_3cehappear.fun5Dynadot LLCAIDEN.NS.CLOUDFLARE.COMNone
34tier_3loyality-program.com4Amazon Registrar, Inc.NS-108.AWSDNS-13.COMNone
35tier_3toryburch.com3CSC CORPORATE DOMAINS, INC.DNS1.CSCDNS.NETRiver Light V, L.P.
36tier_3aeropostale.com2Network Solutions, LLCNS1.P17.DYNECT.NETNone
37tier_32.mediagate.casa2NoneNoneNone
38tier_3chrismoneymaker.com2GoDaddy.com, LLCNS65.DOMAINCONTROL.COMAmaya Services Limited
39tier_3aliexpress.com_LOOP_12NoneNoneNone
40tier_3google.com_LOOP_11NoneNoneNone
41tier_3google.com1MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
42tier_3nissanusa.com1NoneNoneNone
43tier_3ram21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
44tier_3appliancesconnection.com1GoDaddy.com, LLCNS67.DOMAINCONTROL.COMDomains By Proxy, LLC
45tier_3wayfair.com1NoneNoneNone
46tier_33.mediagate.casa1NoneNoneNone
47tier_3venus.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMVenus Fashion, Inc.
48tier_3lulus.com1GoDaddy.com, LLCNS-1116.AWSDNS-11.ORGDomains By Proxy, LLC
49tier_30.mediagate.casa1NoneNoneNone
50tier_3bestsecretflirt.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
51tier_3volume.com1DYNADOT, LLCA.NS.VOLUME.COMNone
52tier_3mergerinvesting.com1NoneNoneNone
53tier_3slotocash.im1Nonedane.ns.cloudflare.com.None
iphostnamecityregionorgpostalcountry_nametiercountanycast
064.32.8.70customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_116nan
1185.107.56.58nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_110nan
264.32.8.68customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_19nan
3185.107.56.60nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_17nan
464.32.8.69customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_16nan
564.32.8.67customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_15nan
6185.107.56.57nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_15nan
7185.107.56.59nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nan
8192.138.218.207nanSeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_38nan
9178.62.225.201nanAmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_34nan
10209.15.13.136nanTorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_218nan
11167.233.8.197static.197.8.233.167.clients.your-server.deNürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_217nan
12192.138.218.139rd.connexity.netSeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_217nan
1352.206.141.190ec2-52-206-141-190.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_213nan
14198.134.116.30nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_213nan
15173.239.53.32nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_212nan
163.226.37.31ec2-3-226-37-31.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212nan
1752.205.177.114ec2-52-205-177-114.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212nan
1852.72.29.7ec2-52-72-29-7.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_211nan
19209.205.202.42static-42-202-205-209.24shells.netNew York CityNew YorkAS55081 24 SHELLS10004United Statestier_211nan
20209.205.202.43static-43-202-205-209.24shells.netNew York CityNew YorkAS55081 24 SHELLS10004United Statestier_211nan
2135.162.164.74ec2-35-162-164-74.us-west-2.compute.amazonaws.comBoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_211nan
22151.101.1.151nanSan FranciscoCaliforniaAS54113 Fastly94107United Statestier_31True
2352.29.135.45ec2-52-29-135-45.eu-central-1.compute.amazonaws.comFrankfurt am MainHesseAS16509 Amazon.com, Inc.60311Germanytier_210nan
2434.225.128.119ec2-34-225-128-119.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210nan
25173.192.101.2418.65.c0ad.ip4.static.sl-reverse.comDallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_29nan
2634.197.67.232ec2-34-197-67-232.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29nan
2788.99.101.106static.106.101.99.88.clients.your-server.deHohen NeuendorfBrandenburgAS24940 Hetzner Online GmbH16540Germanytier_28nan
28100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_313nan
29204.79.197.200a-0001.a-msedge.netRedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_38True
30192.138.218.207nanSeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_38nan
31178.62.225.201nanAmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_34nan
3234.192.40.54ec2-34-192-40-54.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34nan
3352.85.132.55server-52-85-132-55.iad50.r.cloudfront.netAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_33nan
34104.17.224.18nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32True
3592.205.4.117ip-92-205-4-117.ip.secureserver.netStrasbourgGrand EstAS21499 Host Europe GmbH67000Francetier_32nan
3613.107.21.200nanRedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32True
3723.59.250.74a23-59-250-74.deploy.static.akamaitechnologies.comNewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_32nan
38172.217.12.196lga25s63-in-f4.1e100.netCliftonNew JerseyAS15169 Google LLC07015United Statestier_31nan
3923.51.162.53a23-51-162-53.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS16625 Akamai Technologies, Inc.19099United Statestier_31nan
40162.243.10.151nanNew York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_31nan
4124.157.42.211189d2ad3.cst.lightpath.netNew York CityNew YorkAS6128 Cablevision Systems Corp.10004United Statestier_31nan
4296.16.29.13a96-16-29-13.deploy.static.akamaitechnologies.comNew York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31nan
4399.84.176.94server-99-84-176-94.iad89.r.cloudfront.netWashingtonWashington, D.C.AS16509 Amazon.com, Inc.20045United Statestier_31nan
4423.33.138.137a23-33-138-137.deploy.static.akamaitechnologies.comNew York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_31nan
45151.101.1.151nanSan FranciscoCaliforniaAS54113 Fastly94107United Statestier_31True
4688.80.185.92li678-92.members.linode.comLondonEnglandAS63949 Linode, LLCEC1AUnited Kingdomtier_31nan
4723.59.250.96a23-59-250-96.deploy.static.akamaitechnologies.comNewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31nan
48104.22.71.250nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
4945.55.189.248nanCliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_31nan
5052.85.132.46server-52-85-132-46.iad50.r.cloudfront.netAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31nan
51172.67.75.151nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website