Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01451425070292021-02-0864.32.8.70Android
tierdomaincountregistrarname_serversorg
0tier_1bugpoint.net1eNom413, IncorporatedNS1.DNSNUTS.COMNone
1tier_1animehentaitube.net1Heavydomains.net LLCNS1.DNSNUTS.COMNone
2tier_1economictims.com1Domain Landing Zone LLCNS1.DNSNUTS.COMNone
3tier_1alhasanah.net1Deep Dive Domains, LLCNS1.DNSNUTS.COMNone
4tier_1dxnewradio.com1Aquila Domains LLCNS1.DNSNUTS.COMNone
5tier_1aj01.net1Atomicdomainnames.com LLCNS1.DNSNUTS.COMThe Management Group II
6tier_1almanarschool.net1AtlanticFriendNames.com LLCNS1.DNSNUTS.COMNone
7tier_1advancetools.net1DomainSprouts.com LLCNS1.DNSNUTS.COMNone
8tier_1eelfie.com1eNom419, IncorporatedNS1.DNSNUTS.COMNone
9tier_1being-bianca.com1Gozerdomains.com LLCNS1.DNSNUTS.COMThe Management Group II
10tier_2alfik-fik.com81Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
11tier_2track.vcdc.com69Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
12tier_2atnpx.com55GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2media-px.com14GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
14tier_2servedby.flashtalking.com14MESH DIGITAL LIMITEDNS1.P09.DYNECT.NETFlashtalking, Inc.
15tier_2dprtb.com101API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
16tier_2ad.doubleclick.net7MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
17tier_2timply-powidered.com5Amazon Registrar, Inc.NS-1421.AWSDNS-49.ORGWhois Privacy Service
18tier_2click.expmediadirect.com5NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
19tier_2rtbstream.com31API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
20tier_3kbb.com52CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
21tier_3socalhondadealers.com14DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
22tier_3dprtb.com71API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
23tier_3rtbstream.com61API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
24tier_3squirt.org5NAMECHEAP INCNS5.DNSMADEEASY.COMWhoisGuard, Inc.
25tier_3storystudio.sfgate.com3CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
26tier_3btpnative.com31API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
27tier_3robogarden.io3GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
28tier_3searchfrequently.com2GoDaddy.com, LLCNEIL.NS.CLOUDFLARE.COMDomains By Proxy, LLC
29tier_3b.delightcmain.xyz2Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0185.107.56.60AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_119nannan
164.32.8.68Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_118customer.sharktech.netnan
264.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_116customer.sharktech.netnan
3185.107.56.59AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_113nannan
464.32.8.67Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_112customer.sharktech.netnan
564.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_111customer.sharktech.netnan
6185.107.56.57AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_110nannan
7185.107.56.58AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_16nannan
8167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_269static.197.8.233.167.clients.your-server.denan
934.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_243ec2-34-200-146-95.compute-1.amazonaws.comnan
10104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_238nanTrue
1154.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_238ec2-54-84-27-165.compute-1.amazonaws.comnan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_316nannan
13205.185.216.42DallasTexasAS20446 Highwinds Network Group, Inc.75201United Statestier_211map2.hwcdn.netTrue
14104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_210nanTrue
15172.67.74.77San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_27nanTrue
16172.67.134.220San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_27nanTrue
17104.21.6.127San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_27nanTrue
1823.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_352a23-44-217-143.deploy.static.akamaitechnologies.comnan
19209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_316nannan
2035.174.35.73Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_38ec2-35-174-35-73.compute-1.amazonaws.comnan
2134.207.4.240Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_36ec2-34-207-4-240.compute-1.amazonaws.comnan
22158.106.84.60TorontoOntarioAS23498 COGECODATAM5NCanadatier_35desktop.squirt.orgnan
2398.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_33nannan
24172.67.138.156San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
25104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
26104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
27192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_32rd.bizrate.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website