Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02102095940212021-04-1364.32.8.68Safari
tierdomaincountregistrarname_serversorg
0tier_1eagleware.net1Wildzebradomains, LLCNS1.DNSNUTS.COMNone
1tier_1curious-information.net1MidWest Domains LLCNS1.DNSNUTS.COMNone
2tier_1dredown.net1Domainsalsa.com LLCNS1.DNSNUTS.COMNone
3tier_1blessedit.com1eNom387, IncorporatedNS1.DNSNUTS.COMNone
4tier_1economictims.com1Domain Landing Zone LLCNS1.DNSNUTS.COMNone
5tier_1civgames.com1Domainsinthebag.com LLCNS1.DNSNUTS.COMNone
6tier_1beritatrendz.com1Nameselite, LLCNS1.DNSNUTS.COMNone
7tier_1dakmm.com1Private Domains, IncorporatedNS1.DNSNUTS.COMNone
8tier_1alekseypopovv.net1Namearsenal.com LLCNS1.DNSNUTS.COMNone
9tier_1az-khaos.com1EUTurbo.com LLCNS1.DNSNUTS.COMNone
10tier_2btpnav.com501API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
11tier_21496.rawlexi.com41GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
12tier_2americanlisted.com35ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
13tier_2aristo-hag.com25Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
14tier_2track.vcdc.com24Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
15tier_2click.expmediadirect.com18NoneNoneNone
16tier_2asufij.xyz15NoneNoneNone
17tier_2nizephoros-pom.com13Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
18tier_2click.appcast.io9101Domain GRS LtdNS-85.AWSDNS-10.COMNone
19tier_2api.apptap.com8Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
20tier_2redirect.viglink.com8Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
21tier_2link.sylikes.com8MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
22tier_2managerformula.com7NoneNoneNone
23tier_2clk.rtpdn12.com5NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
24tier_2rd.bizrate.com5MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
25tier_2rd.connexity.net5NoneNoneNone
26tier_2btpnative.com51API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
27tier_2infopicked.com5NoneNoneNone
28tier_2survey-smiles.com3Media Elite Holdings LimitedNS1.WOMBATDNS.COMFundacion Privacy Services LTD
29tier_29nl.es3NoneNoneNone
30tier_3irl.com19GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
31tier_3xzb.subeamy.pw15NoneNoneNone
32tier_3us.tideri.com15united domains AGNS.UDAG.DENone
33tier_3click.appcast.io9101Domain GRS LtdNS-85.AWSDNS-10.COMNone
34tier_3s3.amazonaws.com7MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
35tier_3americanlisted.com6ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
36tier_3managerformula.com6NoneNoneNone
37tier_3careerbuilder.com4CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
38tier_3venus.com3GoDaddy.com, LLCNS0.DNSMADEEASY.COMVenus Fashion, Inc.
39tier_3ww1.survey-smiles.com3Media Elite Holdings LimitedNS1.WOMBATDNS.COMFundacion Privacy Services LTD
40tier_3rd.bizrate.com3MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
41tier_3signup.finddreamjobs.com3GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
42tier_3bing.com2MarkMonitor Inc.DNS1.P09.NSONE.NETNone
43tier_3play.google.com2NoneNoneNone
44tier_3music.apple.com2CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
45tier_3btpnative.com11API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
46tier_3google.com_LOOP_11NoneNoneNone
47tier_3storystudio.sfgate.com1CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
48tier_3track.vcdc.com1Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
49tier_3ziprecruiter.com1Safenames LtdCAROL.NS.CLOUDFLARE.COMNone
50tier_3apexfocusgroup.com1NoneNoneNone
51tier_3beyourxfriend.com1GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
52tier_3wayup.com1NAMECHEAP INCKARINA.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
53tier_3casinobonus4u.com1Domain.com, LLCNS104.WEBMASTERS.COMDomain Privacy Service FBO Registrant.
54tier_3nizephoros-pom.com1Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
55tier_3aspiration.com1NAMECHEAP INCNS-1040.AWSDNS-02.ORGPrivacy service provided by Withheld for Privacy ehf
56tier_3us.jobtome.com1GoDaddy.com, LLCCHRIS.NS.CLOUDFLARE.COMJobtome Internantional SA
57tier_3zgallerie.com_LOOP_11NoneNoneNone
58tier_3invictastores.com_LOOP_11NoneNoneNone
59tier_3carinsurance.net1GoDaddy.com, LLCNS-1055.AWSDNS-03.ORGDomains By Proxy, LLC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0185.107.56.60RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_121nannan
164.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_118customer.sharktech.netnan
264.32.8.68Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_118customer.sharktech.netnan
3185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_114nannan
464.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_114customer.sharktech.netnan
5185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_113nannan
664.32.8.67Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_110customer.sharktech.netnan
7185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_17nannan
8209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_31nannan
9198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_242nannan
1035.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_36240.61.209.35.bc.googleusercontent.comnan
11167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_31static.197.8.233.167.clients.your-server.denan
12198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_218nannan
13192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33nannan
1418.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-18-235-67-128.compute-1.amazonaws.comnan
1552.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-52-72-29-7.compute-1.amazonaws.comnan
1654.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-54-208-107-202.compute-1.amazonaws.comnan
1734.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-34-197-176-2.compute-1.amazonaws.comnan
1852.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-52-206-141-190.compute-1.amazonaws.comnan
1944.241.50.49BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_27ec2-44-241-50-49.us-west-2.compute.amazonaws.comnan
20173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_26nannan
213.226.37.31AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-3-226-37-31.compute-1.amazonaws.comnan
22209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_26nannan
23192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_25rd.connexity.netnan
24173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_2518.65.c0ad.ip4.static.sl-reverse.comnan
2552.33.20.119BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_24ec2-52-33-20-119.us-west-2.compute.amazonaws.comnan
2644.239.66.208BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_24ec2-44-239-66-208.us-west-2.compute.amazonaws.comnan
27100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-100-25-52-1.compute-1.amazonaws.comnan
2835.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_315123.171.246.35.bc.googleusercontent.comnan
2952.88.215.122BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_38ec2-52-88-215-122.us-west-2.compute.amazonaws.comnan
3035.165.21.241BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_37ec2-35-165-21-241.us-west-2.compute.amazonaws.comnan
3135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_36240.61.209.35.bc.googleusercontent.comnan
3252.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_36ec2-52-3-4-129.compute-1.amazonaws.comnan
33100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_35pool-100-37-135-2.nycmny.fios.verizon.netnan
34161.35.60.200North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_34nannan
3523.73.235.8EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_33a23-73-235-8.deploy.static.akamaitechnologies.comnan
36199.59.242.153New York CityNew YorkAS395082 Bodis, LLC10004United Statestier_33nannan
37192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_33nannan
38104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
3952.203.36.44AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-52-203-36-44.compute-1.amazonaws.comnan
40157.245.84.7North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
41167.172.139.120North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
4299.84.114.84NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-114-84.ewr52.r.cloudfront.netnan
4354.205.240.192AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-54-205-240-192.compute-1.amazonaws.comnan
4464.227.12.111North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
4567.207.81.229North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_32nannan
4699.84.114.74NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-114-74.ewr52.r.cloudfront.netnan
4752.217.102.38AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
48104.102.251.200New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_32a104-102-251-200.deploy.static.akamaitechnologies.comnan
493.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-3-234-0-165.compute-1.amazonaws.comnan
5052.73.153.209AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-52-73-153-209.compute-1.amazonaws.comnan
51104.102.251.144New York CityNew YorkAS20940 Akamai International B.V.10004United Statestier_32a104-102-251-144.deploy.static.akamaitechnologies.comnan
52209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_31nannan
53204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31a-0001.a-msedge.netTrue
54151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_31nanTrue
55167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_31static.197.8.233.167.clients.your-server.denan
56104.16.174.190San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5752.217.201.208AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website