Daily Threat Intelligence Report

This report contains following information. All tables and graphs are auto-generated.

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain

Content Warning: The following domain names and screenshots contain material that may be harmful or traumatizing to some audiences.

num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
070661170162021-09-0664.32.8.68Chrome
tierdomaincountregistrarname_serversorg
0tier_1282hook.com1Namecatch Zone LLCNS1.DNSNUTS.COMThe Management Group II
1tier_1ahngun.com1Namecroc.com LLCNS1.DNSNUTS.COMNone
2tier_1aj01.net1Atomicdomainnames.com LLCNS1.DNSNUTS.COMThe Management Group II
3tier_1abdato.com1Dropcatching Names LLCNS1.DNSNUTS.COMThe Management Group II
4tier_17peliculas.com1SNAPNAMES 4, LLCNS1.DNSNUTS.COMThe Management Group II
5tier_1129zy.com1SNAPNAMES 10, LLCNS1.DNSNUTS.COMNone
6tier_134only.net1Atomicdomainnames.com LLCNS1.DNSNUTS.COMNone
7tier_1aamorris.net1BullRunDomains.com LLCNS1.DNSNUTS.COMNone
8tier_124hoursforanna.com1NamePal.com #8010 Inc.NS1.DNSNUTS.COMNone
9tier_1animalkun.org1AtlanticFriendNames.com LLCNS1.DNSNUTS.COMStatutory Masking Enabled
10tier_2acrvclk.com9NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
11tier_2clk.rtpdn14.com9NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
12tier_2click.expmediadirect1.com9NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
13tier_2go.dmzjmp.com7NAMECHEAP INCAMY.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
14tier_2antig-hra.com5Amazon Registrar, Inc.NS-1005.AWSDNS-61.NETWhois Privacy Service
15tier_2v4.s.arclk.net4PSI-USA, Inc. dba Domain RobotA.NS14.NETNone
16tier_2xml.sedodna.com2PSI-USA, Inc. dba Domain RobotNS-1222.AWSDNS-24.ORGNone
17tier_2trafficgate.cc2NAMECHEAP INCHANS.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
18tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
19tier_2ww1.ahngun.com1Namecroc.com LLCNS1.DNSNUTS.COMNone
20tier_2ww1.abdato.com1Dropcatching Names LLCNS1.DNSNUTS.COMThe Management Group II
21tier_2juicydataair.ru1FE-RUdave.ns.cloudflare.com.None
22tier_20.juicydataair.ru1FE-RUdave.ns.cloudflare.com.None
23tier_21.juicydataair.ru1FE-RUdave.ns.cloudflare.com.None
24tier_22.juicydataair.ru1FE-RUdave.ns.cloudflare.com.None
25tier_2track.vcdc.com1Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
26tier_2xml.onwardclick.com1NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
27tier_2adserver.encontextadvertising.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
28tier_2adserver.shopnsave.world1NoneNoneNone
29tier_2rtbstream.com11API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
30tier_3stripchat.com7NAMECHEAP INCAMY.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
31tier_3top.faqtoids.com1NoneNoneNone
32tier_3juicydataair.ru1FE-RUdave.ns.cloudflare.com.None
33tier_33.juicydataair.ru1FE-RUdave.ns.cloudflare.com.None
34tier_3top.digitaltrendsradar.com1PDR Ltd. d/b/a PublicDomainRegistry.comGWEN.NS.CLOUDFLARE.COMPrivacy Protect, LLC (PrivacyProtect.org)
35tier_3top.allresultsweb.com1NoneNoneNone
36tier_3shopnsave.world1NoneNoneNone
37tier_3betterhelp.com1GoDaddy.com, LLCNS-103.AWSDNS-12.COMBetterHelp
38tier_3volume.com1DYNADOT LLCA.NS.VOLUME.COMNone
39tier_3amazon.com1NoneNoneNone
40tier_3apple.com1CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
41tier_3bongacams.com1Safenames LtdNS1.BNG-NS.COMNone
42tier_3seek.theweb.com1NoneNoneNone
43tier_3surveystarz.com1GoDaddy.com, LLCNS13.DOMAINCONTROL.COMDomains By Proxy, LLC
44tier_3worldoftanks.eu1NonenNone
45tier_3gua21.proasdf.com1GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0185.107.56.60RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
1185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
264.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_13customer.sharktech.netnan
3185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
464.32.8.68Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_13customer.sharktech.netnan
5185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
664.32.8.67Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_12customer.sharktech.netnan
764.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_11customer.sharktech.netnan
8173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_212nannan
9213.174.155.140WashingtonWashington, D.C.AS39572 DataWeb Global Group B.V.20045United Statestier_29nannan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_29nannan
11172.67.218.230San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_25nanTrue
12178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nannan
1352.73.147.241AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-52-73-147-241.compute-1.amazonaws.comnan
1444.196.216.26AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-44-196-216-26.compute-1.amazonaws.comnan
1534.195.15.110AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-34-195-15-110.compute-1.amazonaws.comnan
1664.190.63.136Frankfurt am MainHesseAS47846 SEDO GmbH60311Germanytier_22nannan
1788.99.101.106Hohen NeuendorfBrandenburgAS24940 Hetzner Online GmbH16540Germanytier_22static.106.101.99.88.clients.your-server.denan
1834.195.129.193AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-34-195-129-193.compute-1.amazonaws.comnan
19104.21.35.112San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_22nanTrue
20209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_22nannan
21167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_21static.197.8.233.167.clients.your-server.denan
2267.227.155.96LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_21nannan
2367.227.241.125LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_31host.encontext.comnan
24209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_21nannan
25143.204.151.83NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_21server-143-204-151-83.ewr52.r.cloudfront.netnan
263.234.3.235AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-3-234-3-235.compute-1.amazonaws.comnan
2717.56.48.13AshlandOregonAS714 Apple Inc.97520United Statestier_21foundationdb.comnan
28104.19.182.41San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
2951.91.200.241RoubaixHauts-de-FranceAS16276 OVH SAS59051 CEDEX 1Francetier_32ip241.ip-51-91-200.eunan
30178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nannan
3166.81.205.246AustinTexasAS40034 Confluence Networks Inc78701United Statestier_31nannan
3267.227.241.125LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_31host.encontext.comnan
3352.2.75.57AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-2-75-57.compute-1.amazonaws.comnan
34172.67.26.187San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
35143.204.142.6NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-143-204-142-6.ewr52.r.cloudfront.netnan
3623.54.68.207PiscatawayNew JerseyAS16625 Akamai Technologies, Inc.08854United Statestier_31a23-54-68-207.deploy.static.akamaitechnologies.comnan
37195.85.23.89KarlínSouth MoravianAS209242 Cloudflare London, LLC186 00Czech Republictier_31net-89-23-conversasro.comTrue
38158.69.125.9MontréalQuebecAS16276 OVH SASH2WCanadatier_31ns521759.ip-158-69-125.netnan
39165.227.96.45CliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_31109327.cloudwaysapps.comnan
4092.223.20.123LuxembourgLuxembourgAS199524 G-Core Labs S.A.L-1882Luxembourgtier_31ed-sl-a123.fe.core.pwnan
41162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_31nannan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website