Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0112113271002020-11-3064.32.8.70Chrome
tierdomaincountregistrarname_serversorg
0tier_1memyselfandpi.net1Catch Domains LLCNS1.DNSNUTS.COMNone
1tier_1squarelion.net1Namesaplenty LLCNS1.DNSNUTS.COMNone
2tier_1605375.com1IServeYourDomain.com LLCNS1.DNSNUTS.COMNone
3tier_1ahirugama.net1SNAPNAMES 19, LLCNS1.DNSNUTS.COMNone
4tier_1shahi.net1Domain Rouge, LLCNS1.DNSNUTS.COMNone
5tier_1melaniemoon.net1Domains of Origin, LLCNS1.DNSNUTS.COMNone
6tier_1risleyitin.net1Pararescuedomains.com, LLCNS1.DNSNUTS.COMNone
7tier_1videopremium.net1DomainsAreForever.net LLCNS1.DNSNUTS.COMNone
8tier_199popbra.com1OregonEU.com LLCNS1.DNSNUTS.COMNone
9tier_110tiposde.com1Top Pick Names LLCNS1.DNSNUTS.COMNone
10tier_2sopho-kat.com27Amazon Registrar, Inc.NS-1009.AWSDNS-62.NETWhois Privacy Service
11tier_2dprtb.com19GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
12tier_2click.expmediadirect.com19NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
13tier_2media-px.com7GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
14tier_2servedby.flashtalking.com7MESH DIGITAL LIMITEDNS1.P09.DYNECT.NETFlashtalking, Inc.
15tier_2build.mediapicker.com7GoDaddy.com, LLCRAQUEL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
16tier_2track.vcdc.com7Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
17tier_2mnason-hec.com6Amazon Registrar, Inc.NS-1205.AWSDNS-22.ORGWhois Privacy Service
18tier_2click.junmediadirect.com6NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
19tier_2btpnative.com6GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
20tier_3irl.com14GoDaddy.com, LLCNS-106.AWSDNS-13.COMDomains By Proxy, LLC
21tier_3socalhondadealers.com7DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
22tier_3turbo-pdf.com7NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
23tier_3loadoverly-thecurrentfile.best4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
24tier_3thefatburner.info4GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
25tier_3loadlatest-theoverlyfile.best3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
26tier_3il.betrivers.com2GoDaddy.com, LLCERIN.NS.CLOUDFLARE.COMRivers IP Holdings, LLC
27tier_3bitcofeed.info2GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
28tier_3macys.com2Network Solutions, LLCA1-135.AKAM.NETNone
29tier_3toovolution.club2NAMECHEAP INCdemi.ns.cloudflare.comWhoisGuard, Inc.
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_115nan
1207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_114nan
2207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_114nan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_18nan
4185.107.56.57RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nan
5185.107.56.59RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nan
637.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
764.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_11customer.sharktech.net
837.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
9185.107.56.60RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_11nan
10209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_225nan
1152.205.210.89AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_220ec2-52-205-210-89.compute-1.amazonaws.com
12198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_219nan
1354.225.132.253AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_215ec2-54-225-132-253.compute-1.amazonaws.com
14205.185.216.10DallasTexasAS20446 Highwinds Network Group, Inc.75201United Statestier_27map2.hwcdn.net
1518.210.49.168AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-18-210-49-168.compute-1.amazonaws.com
16173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_2718.65.c0ad.ip4.static.sl-reverse.com
17104.28.30.109San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_26nan
18198.134.116.18New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_26nan
1994.130.186.231NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_23static.231.186.130.94.clients.your-server.de
2054.173.32.183AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_37ec2-54-173-32-183.compute-1.amazonaws.com
21178.128.246.195AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_37nan
22100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_36pool-100-37-135-2.nycmny.fios.verizon.net
2334.207.4.240AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_34ec2-34-207-4-240.compute-1.amazonaws.com
24162.243.166.170North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nan
25104.248.63.231North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nan
26104.248.50.87North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_33nan
2735.174.35.73AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-35-174-35-73.compute-1.amazonaws.com
28104.27.174.27San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nan
29104.19.235.106San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website