Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
016316563301212021-02-2664.32.8.70Android
tierdomaincountregistrarname_serversorg
0tier_1bugpoint.net1SNAPNAMES 42, LLCNS1.DNSNUTS.COMNone
1tier_1drmommyonline.com1DevilDogDomains.com, LLCNS1.DNSNUTS.COMNone
2tier_1dakmm.com1Private Domains, LLCNS1.DNSNUTS.COMNone
3tier_1feby.net1NamePal.com #8024, LLCNS1.DNSNUTS.COMNone
4tier_118land.net1DuckbilledDomains.com LLCNS1.DNSNUTS.COMNone
5tier_1aellaabroad.com1SNAPNAMES 35, LLCNS1.DNSNUTS.COMNone
6tier_1bamporn.com1SNAPNAMES 50, LLCNS1.DNSNUTS.COMNone
7tier_1being-bianca.com1Gozerdomains.com LLCNS1.DNSNUTS.COMNone
8tier_1globalprintmonitor.org1Domainhawks.net LLCNS1.DNSNUTS.COMNone
9tier_1deltathrottle.com1Pipeline Domains, LLCNS1.DNSNUTS.COMNone
10tier_28205.wcitianka.com58GoDaddy Online Services Cayman Islands LTDNS-1096.AWSDNS-09.ORGNone
11tier_2go.revpush.cc58GoDaddy.com, LLCNS43.DOMAINCONTROL.COMDomains By Proxy, LLC
12tier_2afflat3c1.com58DNC Holdings, IncNS1.PEER1.NETSavvy Investments, LLC Privacy ID# 14674509
13tier_2priceshopinsurance.go2cloud.org58NAMECHEAP INCNS-1511.AWSDNS-60.ORG['Seattle Technology', 'Redacted for Privacy Purposes']
14tier_2alfik-fik.com42Amazon Registrar, Inc.NS-1264.AWSDNS-30.ORGWhois Privacy Service
15tier_2track.vcdc.com24Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
16tier_2atnpx.com17GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
17tier_2dprtb.com131API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
18tier_2ad.doubleclick.net11MarkMonitor, Inc.NS1.GOOGLE.COMGoogle Inc.
19tier_2trackyourmpg.com6GoDaddy Online Services Cayman Islands LTDHUGH.NS.CLOUDFLARE.COMNone
20tier_3priceshopinsurance.com58GoDaddy.com, LLCNS27.DOMAINCONTROL.COMDomains By Proxy, LLC
21tier_3kbb.com17CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
22tier_3storystudio.sfgate.com12CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
23tier_3atnpx.com4GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
24tier_3happymakesite.xyz3Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
25tier_3lulus.com_LOOP_13NoneNoneNone
26tier_3m.placesiteb.xyz3Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
27tier_3squirt.org2NAMECHEAP INCNS5.DNSMADEEASY.COMWhoisGuard, Inc.
28tier_3win2.trustedpush.com2NAMECHEAP INCNS-1142.AWSDNS-14.ORGWhoisGuard, Inc.
29tier_3android-data-alert.com2DANESCO TRADING LTDKEENAN.NS.CLOUDFLARE.COMDANESCO TRADING LTD.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0185.107.56.59AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_117nannan
1185.107.56.60AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_117nannan
264.32.8.67Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_114customer.sharktech.netnan
364.32.8.69Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_114customer.sharktech.netnan
464.32.8.68Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_113customer.sharktech.netnan
564.32.8.70Los AngelesCaliforniaAS46844 Sharktech90009United Statestier_112customer.sharktech.netnan
6185.107.56.58AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_111nannan
7185.107.56.57AmsterdamNorth HollandAS43350 NForce Entertainment B.V.1012Netherlandstier_111nannan
8198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_259nannan
934.199.107.160Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_258ec2-34-199-107-160.compute-1.amazonaws.comnan
1069.172.200.185TorontoOntarioAS19324 Dosarrest Internet Security LTDM5NCanadatier_258maxbounty.comnan
11167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_224static.197.8.233.167.clients.your-server.denan
1254.84.27.165Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_223ec2-54-84-27-165.compute-1.amazonaws.comnan
1334.200.146.95Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_221ec2-34-200-146-95.compute-1.amazonaws.comnan
1434.198.147.111Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_220ec2-34-198-147-111.compute-1.amazonaws.comnan
1552.205.36.237Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_219ec2-52-205-36-237.compute-1.amazonaws.comnan
1652.20.195.125Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_219ec2-52-20-195-125.compute-1.amazonaws.comnan
17209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_216nannan
18198.71.233.138AshburnVirginiaAS26496 GoDaddy.com, LLC20149United Statestier_358ip-198-71-233-138.ip.secureserver.netnan
1923.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_317a23-44-217-143.deploy.static.akamaitechnologies.comnan
2098.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_312nannan
21104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
22100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_34pool-100-37-135-2.nycmny.fios.verizon.netnan
23172.67.74.77San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
24158.106.84.60TorontoOntarioAS23498 COGECODATAM5NCanadatier_32squirt.orgnan
25104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
26104.21.25.82San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
2734.206.66.177Virginia BeachVirginiaAS14618 Amazon.com, Inc.23452United Statestier_31ec2-34-206-66-177.compute-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website