Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01531574700132021-04-1064.32.8.68Safari
tierdomaincountregistrarname_serversorg
0tier_1nanbaka.tv1Domain Pickup LLCNS1.DNSNUTS.COMThe Management Group II
1tier_1ddtpulse.com1Gozerdomains.com LLCNS1.DNSNUTS.COMThe Management Group II
2tier_1brasilonline.tv1Sterling Domains LLCNS1.DNSNUTS.COMNone
3tier_1addcomponent.com1Slow Putt Domains LLCNS1.DNSNUTS.COMThe Management Group II
4tier_1elektrononline.net1Blue Angel Domains LLCNS1.DNSNUTS.COMNone
5tier_1javhihi.tv1Exclusive Domain Find LLCNS1.DNSNUTS.COMNone
6tier_1ruby-docs.org1BullRunDomains.com LLCNS1.DNSNUTS.COMStatutory Masking Enabled
7tier_1antiilluminati.net1Hawthornedomains.com LLCNS1.DNSNUTS.COMNone
8tier_1bttorrents.net1Fine Grain Domains, LLCNS1.DNSNUTS.COMThe Management Group II
9tier_1dashitz.com1Name Nelly CorporationNS1.DNSNUTS.COMNone
10tier_2btpnav.com481API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_21496.rawlexi.com42NoneNoneNone
12tier_2americanlisted.com37ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
13tier_2click.expmediadirect.com20NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
14tier_2click.appcast.io19101Domain GRS LtdNS-85.AWSDNS-10.COMNone
15tier_2asufij.xyz12NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
16tier_29nl.es12NoneNoneNone
17tier_2newre-conversions.clickmeter.com12REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
18tier_2us.tideri.com8united domains AGNS.UDAG.DENone
19tier_2nizephoros-pom.com7Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
20tier_2trk.jometer.com7Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
21tier_2infopicked.com5NAMECHEAP INCNS0.DNSMADEEASY.COMPrivacy service provided by Withheld for Privacy ehf
22tier_2api.apptap.com5Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
23tier_2api.mplayit.com5Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
24tier_2whatjobs.com5123-Reg LimitedVIDA.NS.CLOUDFLARE.COMNone
25tier_2ring.joveo.com5Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
26tier_2track.vcdc.com4Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
27tier_2btpnative.com41API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
28tier_2rtbstream.com31API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
29tier_2aristo-hag.com3Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGNone
30tier_3xzb.subeamy.pw12NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
31tier_3us.tideri.com11united domains AGNS.UDAG.DENone
32tier_3managerformula.com5NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
33tier_3americanlisted.com5ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
34tier_3bing.com3MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
35tier_3click.appcast.io_LOOP_13NoneNoneNone
36tier_3us.jobsora.com3NAMECHEAP INCELLIOT.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
37tier_3dollarshaveclub.com3GoDaddy.com, LLCNS-1465.AWSDNS-55.ORGDomains By Proxy, LLC
38tier_3signup.finddreamjobs.com3GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
39tier_3runnewest-bestextremelyfile.best2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
40tier_3whatjobs.com2123-Reg LimitedVIDA.NS.CLOUDFLARE.COMNone
41tier_3careerbuilder.com2CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
42tier_3signup.careersandjobs.co2GoDaddy.com, LLCalexis.ns.cloudflare.comDomains By Proxy, LLC
43tier_3s3.amazonaws.com2MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
44tier_3worldoftanks.com1CSC CORPORATE DOMAINS, INC.NS1.WARGAMING.NETWargaming.net Limited
45tier_3click.appcast.io1101Domain GRS LtdNS-85.AWSDNS-10.COMNone
46tier_3toryburch.com1CSC CORPORATE DOMAINS, INC.DNS1.CSCDNS.NETRiver Light V, L.P.
47tier_3upward.careers1GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
48tier_3volume.com1DYNADOT, LLCA.NS.VOLUME.COMNone
49tier_3feed.int.jobble.com1GoDaddy.com, LLCNS-1238.AWSDNS-26.ORGDomains By Proxy, LLC
50tier_3jobs.jobget.com1Amazon Registrar, Inc.NS-1314.AWSDNS-36.ORGNone
51tier_3higher-hire.com1Name.com, Inc.NS1GMZ.NAME.COMEverlong Media, LLC
52tier_3trk.careerbliss.com1GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
53tier_3venturefizz.com1GoDaddy.com, LLCELLIOT.NS.CLOUDFLARE.COMNone
54tier_3us.jobtome.com1GoDaddy.com, LLCCHRIS.NS.CLOUDFLARE.COMJobtome Internantional SA
55tier_3landing.cdllife.com1GoDaddy.com, LLCAMY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
56tier_3ram21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
57tier_3rd.bizrate.com1MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
58tier_3nextcareernow.com1GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
59tier_3jobleads.com1united domains AGCRUZ.NS.CLOUDFLARE.COMNone
iphostnamecityregionorgpostalcountry_nametiercountanycast
064.32.8.67customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_116nan
1185.107.56.59nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_112nan
2185.107.56.60nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_111nan
364.32.8.70customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_18nan
464.32.8.69customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_18nan
564.32.8.68customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_18nan
6185.107.56.57nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_16nan
7185.107.56.58nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_15nan
8209.15.13.136nanTorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_255nan
9198.54.112.216nanSan JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nan
1035.209.61.240240.61.209.35.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_35nan
11198.134.116.30nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_220nan
1223.21.166.230ec2-23-21-166-230.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210nan
1352.3.4.129ec2-52-3-4-129.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29nan
14100.25.52.1ec2-100-25-52-1.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31nan
1554.235.205.204ec2-54-235-205-204.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28nan
1635.246.171.123123.171.246.35.bc.googleusercontent.comFrankfurt am MainHesseAS15169 Google LLC60311Germanytier_311nan
1752.33.20.119ec2-52-33-20-119.us-west-2.compute.amazonaws.comBoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_26nan
1852.206.141.190ec2-52-206-141-190.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26nan
19209.132.243.15nanLos AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_26nan
2044.241.50.49ec2-44-241-50-49.us-west-2.compute.amazonaws.comBoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_25nan
2199.84.114.53server-99-84-114-53.ewr52.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_25nan
22173.192.101.2418.65.c0ad.ip4.static.sl-reverse.comDallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_25nan
23104.26.6.145nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_25True
2418.235.67.128ec2-18-235-67-128.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24nan
25167.233.8.197static.197.8.233.167.clients.your-server.deNürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_24nan
2623.21.53.13ec2-23-21-53-13.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24nan
27192.138.218.207nanSeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_23nan
2835.246.171.123123.171.246.35.bc.googleusercontent.comFrankfurt am MainHesseAS15169 Google LLC60311Germanytier_311nan
2935.165.21.241ec2-35-165-21-241.us-west-2.compute.amazonaws.comBoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_37nan
3052.88.215.122ec2-52-88-215-122.us-west-2.compute.amazonaws.comBoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_35nan
3135.209.61.240240.61.209.35.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_35nan
32100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_33nan
33104.26.15.111nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33True
34151.101.1.9nanSan FranciscoCaliforniaAS54113 Fastly94107United Statestier_33True
3523.38.167.192a23-38-167-192.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_32nan
3652.20.53.118ec2-52-20-53-118.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32nan
3723.38.167.227a23-38-167-227.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_32nan
38204.79.197.200a-0001.a-msedge.netRedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32True
39104.21.10.65nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32True
40104.17.47.14nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32True
4152.217.80.166s3-1.amazonaws.comAshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32nan
42104.26.7.145nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
43162.213.61.95sv4-sl-b95.fe.core.pwSunnyvaleCaliforniaAS199524 G-Core Labs S.A.94089United Statestier_31nan
44100.25.52.1ec2-100-25-52-1.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31nan
4599.84.47.14server-99-84-47-14.ewr52.r.cloudfront.netNewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31nan
4623.38.170.41a23-38-170-41.deploy.static.akamaitechnologies.comNewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31nan
4767.227.172.40nanLansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_31nan
48172.67.26.187nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
4923.38.167.202a23-38-167-202.deploy.static.akamaitechnologies.comPhiladelphiaPennsylvaniaAS20940 Akamai International B.V.19099United Statestier_31nan
50172.67.72.65nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
5154.234.245.31ec2-54-234-245-31.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31nan
5234.107.171.149149.171.107.34.bc.googleusercontent.comKansas CityMissouriAS15169 Google LLC64121United Statestier_31True
53104.210.37.77nanSan JoseCaliforniaAS8075 Microsoft Corporation95112United Statestier_31nan
54104.17.48.14nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True
5513.107.21.200nanRedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31True
56207.38.44.116cbsmtp1.careerbliss.comLos AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_31nan
57104.26.12.118nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31True

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website