Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0216231748002020-11-0264.32.8.70Iphone
tierdomaincountregistrarname_serversorg
0tier_1veacanal.net1SNAPNAMES 3, LLCNS1.DNSNUTS.COMNone
1tier_1mirrorfile.net1NamePal.com #8021, LLCNS1.DNSNUTS.COMNone
2tier_1therebels.biz1UdomainName.com LLCns2.dnsnuts.comNone
3tier_1brasilonline.tv1Sterling Domains LLCNS1.DNSNUTS.COMNone
4tier_1movietrucks.net1SNAPNAMES 29, LLCNS1.DNSNUTS.COMNone
5tier_1trfrm.net1Goldmine Domains LLCNS1.DNSNUTS.COMNone
6tier_1nod327.net1NamePanther.com LLCNS1.DNSNUTS.COMNone
7tier_1iptv-shop.net1Domain Locale, LLCNS1.DNSNUTS.COMNone
8tier_1esavefrom.net1NameSnapper LLCNS1.DNSNUTS.COMNone
9tier_1orangegfs.com1Sicherregister, LLCNS1.DNSNUTS.COMNone
10tier_2track.vcdc.com71Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
11tier_2go.trackinz.com67NAMECHEAP INCNS-1139.AWSDNS-14.ORGWhoisGuard, Inc.
12tier_2infopicked.com67NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
13tier_2p246485.infopicked.com39NoneNoneNone
14tier_2btpnative.com25GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
15tier_2usa.ced-max.com23Amazon Registrar, Inc.NS-1305.AWSDNS-35.ORGWhois Privacy Service
16tier_2p274639.infopicked.com22NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
17tier_2atnpx.com15GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
18tier_2changeslots.com14Instra Corporation Pty Ltd.CLEO.NS.CLOUDFLARE.COMREDACTED FOR PRIVACY
19tier_2usd.ced-max.com11Amazon Registrar, Inc.NS-1305.AWSDNS-35.ORGWhois Privacy Service
20tier_3checkthistime.com67NAMECHEAP INCNS-1262.AWSDNS-29.ORGWhoisGuard, Inc.
21tier_3track.vcdc.com24Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
22tier_3kbb.com15CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
23tier_3blog.sfgate.com14CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
24tier_3theconnectvpn.com14DonDominio (SCIP)ARNOLD.NS.CLOUDFLARE.COMSoluciones Corporativas IP, c/o Whois Proxy
25tier_3socalhondadealers.com3DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
26tier_3apple.com2CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
27tier_3nissanusa.com2MarkMonitor, Inc.EDNS2.ULTRADNS.BIZNissan North America, Inc
28tier_3med-journal.org1NAMECHEAP INCNS.LIQUIDWEB.COMWhoisGuard, Inc.
29tier_3gladmpath.xyz1Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_138nan
1207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_130nan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_125nan
3207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_120nan
4185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_18nan
5185.107.56.60RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_16nan
637.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nan
737.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nan
8185.107.56.58RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nan
9185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nan
10173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_214218.65.c0ad.ip4.static.sl-reverse.com
1134.226.252.28Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_267ec2-34-226-252-28.compute-1.amazonaws.com
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_230nan
13144.76.0.242NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_221static.242.0.76.144.clients.your-server.de
1454.225.132.253Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_219ec2-54-225-132-253.compute-1.amazonaws.com
15144.76.1.130NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_219static.130.1.76.144.clients.your-server.de
1694.130.185.237NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_218static.237.185.130.94.clients.your-server.de
17209.132.243.15WyomingMichiganAS7296 Alchemy Communications, Inc.49509United Statestier_217nan
1852.205.210.89Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_215ec2-52-205-210-89.compute-1.amazonaws.com
19204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_214204.44.79.214.static.quadranet.com
20157.245.227.32Santa ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_367nan
21138.201.252.161GeldernNorth Rhine-WestphaliaAS24940 Hetzner Online GmbH47608Germanytier_323proxy.traffic.club
22151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_314nan
23104.27.187.165New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_311nan
2423.33.129.176New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_38a23-33-129-176.deploy.static.akamaitechnologies.com
2523.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_37a23-44-217-143.deploy.static.akamaitechnologies.com
26172.67.181.234New York CityNew YorkAS13335 Cloudflare, Inc.10004United Statestier_33nan
2734.207.4.240Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_32ec2-34-207-4-240.compute-1.amazonaws.com
2835.174.35.73Virginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_31ec2-35-174-35-73.compute-1.amazonaws.com
2923.194.108.21SomersetNew JerseyAS16625 Akamai Technologies, Inc.08875United Statestier_31a23-194-108-21.deploy.static.akamaitechnologies.com

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website