Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
017418363101222021-03-0764.32.8.70Safari
tierdomaincountregistrarname_serversorg
0tier_1ggulbam27.com1SNAPNAMES 32, LLCNS1.DNSNUTS.COMNone
1tier_1economictims.com1Domain Landing Zone LLCNS1.DNSNUTS.COMNone
2tier_1clipxplore.com1SouthNames, LLCNS1.DNSNUTS.COMNone
3tier_1face2facethemagazine.com1Domaininthehole.com LLCNS1.DNSNUTS.COMNone
4tier_1chastnoevideo.net1SNAPNAMES 90, LLCNS1.DNSNUTS.COMNone
5tier_1akeremuna2018.com1Domain Secure LLCNS1.DNSNUTS.COMNone
6tier_1civgames.com1Domainsinthebag.com LLCNS1.DNSNUTS.COMNone
7tier_1bagustekno.net1Zone of Domains LLCNS1.DNSNUTS.COMNone
8tier_1aiss.cc1Top Shelf Domains LLCNS1.DNSNUTS.COMNone
9tier_1cloudfilezz.com1Lionshare Domains, LLCNS1.DNSNUTS.COMNone
10tier_2click.expmediadirect.com59NAMECHEAP INCNS1.LINODE.COMWhoisGuard, Inc.
11tier_2rqhere2.com39NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMWhoisGuard, Inc.
12tier_2dprtb.com351API GmbHNS1.DNSIMPLE.COMREDACTED FOR PRIVACY
13tier_21496.wcitianka.com33NoneNoneNone
14tier_2americanlisted.com31ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_2track.vcdc.com26Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
16tier_2clk.rtpdn12.com22NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
17tier_2rd.leewardjobs.com18GoDaddy.com, LLCNS-1391.AWSDNS-45.ORGDomains By Proxy, LLC
18tier_2open.app.jobrapido.com17Marcaria.com International, Inc.NS-CLOUD-D1.GOOGLEDOMAINS.COMGDPR Masked
19tier_2us.jobrapido.com17Marcaria.com International, Inc.NS-CLOUD-D1.GOOGLEDOMAINS.COMGDPR Masked
20tier_3healthemerge.info22GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
21tier_3medicomatic.info18GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
22tier_3thecryptomoney.info18GoDaddy.com, LLCMOLLY.NS.CLOUDFLARE.COMNone
23tier_3fitnessdial.club17GoDaddy.com, LLCmolly.ns.cloudflare.comNone
24tier_3click.appcast.io8101Domain GRS LtdNS-85.AWSDNS-10.COMNone
25tier_3open.app.jobrapido.com_LOOP_16NoneNoneNone
26tier_3uber.com5MarkMonitor, Inc.EDNS126.ULTRADNS.BIZUber Technologies, Inc.
27tier_3neuvoo.com4NoneNoneNone
28tier_3performcompletely-thelatestfile.best4NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
29tier_3performlatest-thecompletelyfile.best3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMWhoisGuard, Inc.
iphostnamecityregionorgpostalcountry_nametiercountanycast
064.32.8.70customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_119nan
164.32.8.68customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_118nan
2185.107.56.60nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_117nan
364.32.8.69customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_116nan
464.32.8.67customer.sharktech.netLos AngelesCaliforniaAS46844 Sharktech90009United Statestier_115nan
5185.107.56.57nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_115nan
6185.107.56.58nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_112nan
7185.107.56.59nanRotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_112nan
8198.134.116.30nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_259nan
9209.15.13.136nanTorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_246nan
10167.99.3.175nanNorth BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_239nan
11198.54.112.216nanSan JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_233nan
1235.209.61.240240.61.209.35.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_231nan
13167.233.8.197static.197.8.233.167.clients.your-server.deNürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_226nan
14173.239.53.32nanNew York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_224nan
15178.33.228.114ns3021656.ip-178-33-228.euRoubaixHauts-de-FranceAS16276 OVH SAS59051 CEDEX 1Francetier_217nan
16100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_318nan
173.226.165.125ec2-3-226-165-125.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23458United Statestier_29nan
18100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_318nan
19172.67.221.83nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314True
20172.67.134.123nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311True
21172.67.167.220nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311True
22104.21.25.189nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_311True
23172.67.210.14nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_310True
24104.21.42.202nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_38True
25104.21.34.37nanSan FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37True
2654.210.35.174ec2-54-210-35-174.compute-1.amazonaws.comAshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_37nan
27104.36.195.150nanWashingtonWashington, D.C.AS63086 Uber Technologies, Inc20045United Statestier_34nan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website