Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0250248554002020-10-0164.32.8.69Chrome
tierdomaincountregistrarname_serversorg
0tier_1umdstudents.com1NamePal.com #8017, LLCNS1.DNSNUTS.COMNone
1tier_1educationalgamesdepot.com1ColumbiaNames.com LLCNS1.DNSNUTS.COMNone
2tier_1sodoityourself.com1Domainarmada.com LLCNS1.DNSNUTS.COMNone
3tier_1nl-fiction.com1WillametteNames.com LLCNS1.DNSNUTS.COMNone
4tier_1jikbakguri.com1SNAPNAMES 40, LLCNS1.DNSNUTS.COMNone
5tier_1builtv.com1SNAPNAMES 10, LLCNS1.DNSNUTS.COMNone
6tier_1bagustekno.net1Zone of Domains LLCNS1.DNSNUTS.COMNone
7tier_1elalmaesunpoema.com1Domain Name Root LLCNS1.DNSNUTS.COMNone
8tier_1littlewolfrun.net1Atomicdomainnames.com LLCNS1.DNSNUTS.COMNone
9tier_1early-childhood-education-programs.com1Slow Motion Domains LLCNS1.DNSNUTS.COMNone
10tier_3btpnative.com19GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
11tier_3roadtoyourhealth.info15GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
12tier_3wix.com15GoDaddy.com, LLCNS1.P14.DYNECT.NETWix.com, LTD.
13tier_3dprtb.com13GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
14tier_3crowngrandcasino.info12GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
15tier_3google.com_LOOP_16NoneNoneNone
16tier_3creditbracket.com6GoDaddy.com, LLCNS-1273.AWSDNS-31.ORGDomains By Proxy, LLC
17tier_3daytrading.com4GoDaddy.com, LLCNS21.DOMAINCONTROL.COMDomains By Proxy, LLC
18tier_3irl.com4GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
19tier_3toovolution.club3NAMECHEAP INCdemi.ns.cloudflare.comWhoisGuard, Inc.
20tier_2click.expmediadirect.com28NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
21tier_2btpnative.com17GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
22tier_2infopicked.com16NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
23tier_210.trackints.com15NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
24tier_2p274639.infopicked.com15NoneNoneNone
25tier_2dprtb.com14GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
26tier_2usd.mnason-hec.com9Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
27tier_2api.quotes.com9Internet Domain Service BS Corp.NS-CANADA.TOPDNS.COMWhois Privacy Corp.
28tier_2usa.julius-nym.com7Amazon Registrar, Inc.NS-1237.AWSDNS-26.ORGWhois Privacy Service
29tier_2clk.rtpdn11.com7NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_131nan
1207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_131nan
2207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_130nan
3207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_127nan
437.48.65.149AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nan
564.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_12customer.sharktech.net
637.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nan
782.192.82.226SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_11nan
837.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
982.192.82.225SoestUtrechtAS60781 LeaseWeb Netherlands B.V.3765Netherlandstier_11nan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_231nan
11100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_213pool-100-37-135-2.nycmny.fios.verizon.net
12172.67.181.25New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_37nan
13172.67.153.207New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_37nan
14104.27.131.174Atlantic CityNew JerseyAS13335 Cloudflare, Inc.08404United Statestier_36nan
15185.230.61.163San JoseCaliforniaAS58182 Wix.com Ltd.95119United Statestier_36nan
16185.230.61.179San JoseCaliforniaAS58182 Wix.com Ltd.95119United Statestier_35nan
1799.83.237.35SeattleWashingtonAS16509 Amazon.com, Inc.98108United Statestier_35a44211ae10448446a.awsglobalaccelerator.com
18178.79.142.48LondonEnglandAS63949 Linode, LLCEC1AUnited Kingdomtier_34li198-48.members.linode.com
19185.230.61.98San JoseCaliforniaAS58182 Wix.com Ltd.95119United Statestier_34nan
20173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_23418.65.c0ad.ip4.static.sl-reverse.com
21209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_231nan
22198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_228nan
23108.168.193.185DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_216b9.c1.a86c.ip4.static.sl-reverse.com
2454.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23457United Statestier_214ec2-54-225-132-253.compute-1.amazonaws.com
25173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_213nan
26100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_213pool-100-37-135-2.nycmny.fios.verizon.net
2752.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23457United Statestier_213ec2-52-205-210-89.compute-1.amazonaws.com
2834.196.151.230Virginia BeachVirginiaAS14618 Amazon.com, Inc.23457United Statestier_210ec2-34-196-151-230.compute-1.amazonaws.com
295.79.68.236AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_29nan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website