Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
0117118232002020-12-2164.32.8.70Chrome
tierdomaincountregistrarname_serversorg
0tier_1javupto.net1! #1 Host Canada, Inc.NS1.DNSNUTS.COMNone
1tier_1ahirugama.net1eNom2, Inc.NS1.DNSNUTS.COMThe Management Group II
2tier_1kamibbs.biz1UdomainName.com LLCns2.dnsnuts.comNone
3tier_1gorgeoustrends.net1Free Drop Zone LLCNS1.DNSNUTS.COMNone
4tier_1hsplay.net1Bonam Fortunam Domains, LLCNS1.DNSNUTS.COMNone
5tier_1digitaldartsco.com1eNomEU, Inc.NS1.DNSNUTS.COMNone
6tier_1ilbaa.com1Domaining Oro, LLCNS1.DNSNUTS.COMThe Management Group II
7tier_1digitalapeel.com1Namesource LLCNS1.DNSNUTS.COMNone
8tier_1lostuyos.net1Domaining Oro, LLCNS1.DNSNUTS.COMThe Management Group II
9tier_1makeaboard.net1TravelDomains, IncorporatedNS1.DNSNUTS.COMNone
10tier_3turbo-pdf.com12NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
11tier_3system-alert-notification.com5NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
12tier_3track.vcdc.com4Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
13tier_3boot-upcompletely-theprogressivefile.best3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
14tier_3boot-upprecise-theintenselyfile.best3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
15tier_3vpnprime.net2NAMECHEAP INCNS-1167.AWSDNS-17.ORGWhoisGuard, Inc.
16tier_3google.com_LOOP_12NoneNoneNone
17tier_3maccleanbooster.com2NAMECHEAP INCNS-1293.AWSDNS-33.ORGWhoisGuard, Inc.
18tier_3kbb.com2CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
19tier_3macys.com2Network Solutions, LLCA1-135.AKAM.NETMacy's Systems and Technology, Inc.
20tier_2clk.rtpdn12.com16NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
21tier_2click.junmediadirect.com14NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
22tier_2click.expmediadirect.com12NameCheap, Inc.NS1.LINODE.COMNone
23tier_2track.vcdc.com11Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
24tier_2rqhere2.com10NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMWhoisGuard, Inc.
25tier_2build.mediapicker.com8GoDaddy.com, LLCRAQUEL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
26tier_2euphe-gun.com6Amazon Registrar, Inc.NS-1325.AWSDNS-37.ORGWhois Privacy Service
27tier_2infopicked.com4NAMECHEAP INCNS0.DNSMADEEASY.COMWhoisGuard, Inc.
28tier_2btpnative.com41API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
29tier_2dprtb.com3GoDaddy.com, LLCNS1.DNSIMPLE.COMDomains By Proxy, LLC
ipcityregionorgpostalcountry_nametiercounthostname
0207.244.67.216ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_116nan
1207.244.67.215ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_110nan
2207.244.67.218ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_18nan
3207.244.67.214ManassasVirginiaAS30633 Leaseweb USA, Inc.20108United Statestier_14nan
4185.107.56.59AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_12nan
5185.107.56.57AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_12nan
637.48.65.151AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nan
737.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
8185.107.56.60AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_11nan
937.48.65.148AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_11nan
10178.128.246.195AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_317nan
1175.101.207.6Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_38ec2-75-101-207-6.compute-1.amazonaws.com
12195.201.92.254NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_34static.254.92.201.195.clients.your-server.de
1313.225.222.26New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_32server-13-225-222-26.jfk51.r.cloudfront.net
14100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.net
1523.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-44-217-143.deploy.static.akamaitechnologies.com
1623.41.189.63NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-41-189-63.deploy.static.akamaitechnologies.com
1734.214.215.250PortlandOregonAS16509 Amazon.com, Inc.97293United Statestier_31ec2-34-214-215-250.us-west-2.compute.amazonaws.com
183.15.168.232ColumbusOhioAS16509 Amazon.com, Inc.43221United Statestier_31ec2-3-15-168-232.us-east-2.compute.amazonaws.com
1913.225.222.16New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_31server-13-225-222-16.jfk51.r.cloudfront.net
20173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_218nan
21198.134.116.18New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_214nan
22198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_212nan
23167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_210nan
24209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_29nan
2518.210.49.168Virginia BeachVirginiaAS14618 Amazon.com, Inc.23464United Statestier_28ec2-18-210-49-168.compute-1.amazonaws.com
26173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_2618.65.c0ad.ip4.static.sl-reverse.com
27209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_25nan
28144.76.0.242NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_24static.242.0.76.144.clients.your-server.de
29178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_24nan

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website