Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
027728812160152021-04-0774.63.241.23Android
tierdomaincountregistrarname_serversorg
0tier_1teamice.us1Communi Gal Communications Ltd.ns2.commonmx.comNone
1tier_1girlystuff.info1Dynadot, LLCNS1.COMMONMX.COMNone
2tier_1uhmanoa.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1studiojimbo.io1Dynadot, LLCNS1.COMMONMX.COMNone
4tier_1786.name1NoneNoneNone
5tier_1misopan.net1DYNADOT, LLCNS1.COMMONMX.COMNone
6tier_1yume-baken.com1CommuniGal Communication Ltd.NS1.COMMONMX.COMNone
7tier_1editimage.org1GoDaddy.com, LLCNS1.COMMONMX.COMVirtua Drug Ltd
8tier_1mooncake.us1Communi Gal Communications Ltd.ns2.commonmx.comNone
9tier_1aashagupta.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158839965
10tier_2rugab-ans.com123Amazon Registrar, Inc.NS-1165.AWSDNS-17.ORGWhois Privacy Service
11tier_2btpnav.com1031API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2atnpx.com77GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2click.expmediadirect.com62NoneNoneNone
14tier_2api.apptap.com62Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
15tier_2redirect.viglink.com62Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
16tier_2link.sylikes.com62MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
17tier_2rd.bizrate.com56NoneNoneNone
18tier_2rd.connexity.net45NoneNoneNone
19tier_2api.mplayit.com42Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
20tier_2ad.doubleclick.net21NoneNoneNone
21tier_2media-px.com15GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
22tier_2trackyourmpg.com11GoDaddy Online Services Cayman Islands LTDHUGH.NS.CLOUDFLARE.COMNone
23tier_2btpnative.com101API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
24tier_2infopicked.com10NoneNoneNone
25tier_262881.click.validclick.net5Safenames LtdNS1.FULLMAILBOX.COMNone
26tier_262843.click.validclick.net5Safenames LtdNS1.FULLMAILBOX.COMNone
27tier_262885.click.validclick.net4Safenames LtdNS1.FULLMAILBOX.COMNone
28tier_2servedby.flashtalking.com4MESH DIGITAL LIMITEDNS1.P09.DYNECT.NETFlashtalking, Inc.
29tier_2rd.connexity.net_LOOP_14NoneNoneNone
30tier_3robogarden.io63GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
31tier_3kbb.com25CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
32tier_3storystudio.sfgate.com18CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
33tier_3frontgate.com13Network Solutions, LLCNS1.HSN.NETCornerstone Brands, Inc.
34tier_3overstock.com10MarkMonitor, Inc.DNS1.P01.NSONE.NETOverstock.com, Inc - TMA606142
35tier_3venus.com9GoDaddy.com, LLCNS0.DNSMADEEASY.COMVenus Fashion, Inc.
36tier_3rd.bizrate.com7NoneNoneNone
37tier_3opticsplanet.com7GoDaddy.com, LLCNS1.ECENTRIA.COMECENTRIA IPH, LLC
38tier_3berettausa.com6Network Solutions, LLCNS1.AMERICANEAGLE.COMBeretta USA Corp
39tier_3m.placesiteb.xyz6Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
40tier_3socalhondadealers.com4NoneNoneNone
41tier_3m.gladplacespin.xyz4Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
42tier_3ballarddesigns.com_LOOP_12NoneNoneNone
43tier_3neuvoo.com1MarkMonitor, Inc.NS-1302.AWSDNS-34.ORGTalent.com
44tier_3b.playspind.xyz1Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
45tier_3win2.trustedpush.com1NoneNoneNone
46tier_3godaddy.com1GoDaddy.com, LLCA1-245.AKAM.NETGo Daddy Operating Company, LLC
47tier_3hrblock.com1MarkMonitor, Inc.NS3.HRBLOCK.COMHRB Innovations Inc.
48tier_3frontgate.com_LOOP_11NoneNoneNone
49tier_3media-px.com1GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
50tier_3birkenstock.com1PSI-USA, Inc. dba Domain RobotA.NS14.NETBIRKENSTOCK SALES GMBH
51tier_3eharmony.com1NoneNoneNone
52tier_3overstock.com_LOOP_11NoneNoneNone
53tier_3fanatics.com_LOOP_11NoneNoneNone
54tier_3harryanddavid.com_LOOP_11NoneNoneNone
55tier_3win3.trustedpush.com1NoneNoneNone
56tier_3invictastores.com_LOOP_11NoneNoneNone
57tier_3lampsplus.com_LOOP_11NoneNoneNone
58tier_3welry.com1Amazon Registrar, Inc.NS-1079.AWSDNS-06.ORGWhois Privacy Service
59tier_3opticsplanet.com_LOOP_11NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_130nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
3207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_118nannan
5206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_117nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_117nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
882.192.82.227AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_12nannan
9185.107.56.200RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nannan
10192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_37rd.bizrate.comnan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_2115nannan
12198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_262nannan
13192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_245rd.connexity.netnan
14104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_242nanTrue
1534.197.67.232AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_237ec2-34-197-67-232.compute-1.amazonaws.comnan
1634.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_236ec2-34-225-128-119.compute-1.amazonaws.comnan
1752.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_234ec2-52-206-141-190.compute-1.amazonaws.comnan
1852.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_233ec2-52-205-177-114.compute-1.amazonaws.comnan
19104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_227nanTrue
203.226.37.31AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_226ec2-3-226-37-31.compute-1.amazonaws.comnan
2152.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_224ec2-52-72-29-7.compute-1.amazonaws.comnan
2218.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-18-235-67-128.compute-1.amazonaws.comnan
2334.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_222ec2-34-197-176-2.compute-1.amazonaws.comnan
2434.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_221ec2-34-207-43-7.compute-1.amazonaws.comnan
2552.206.108.38AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_219ec2-52-206-108-38.compute-1.amazonaws.comnan
26204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_218204.44.79.214.static.quadranet.comnan
2754.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_218ec2-54-208-107-202.compute-1.amazonaws.comnan
28172.67.134.220San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_214nanTrue
29173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_21018.65.c0ad.ip4.static.sl-reverse.comnan
30172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_347nanTrue
3123.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_325a23-44-217-143.deploy.static.akamaitechnologies.comnan
3298.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_318nannan
33104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_316nanTrue
34184.87.71.113NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_310a184-87-71-113.deploy.static.akamaitechnologies.comnan
35104.77.221.88New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_310a104-77-221-88.deploy.static.akamaitechnologies.comnan
36100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_39pool-100-37-135-2.nycmny.fios.verizon.netnan
37192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_37rd.bizrate.comnan
38152.195.32.168AshburnVirginiaAS15133 MCI Communications Services, Inc. d/b/a Verizon Business20147United Statestier_37nanTrue
3923.73.224.199EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_36a23-73-224-199.deploy.static.akamaitechnologies.comnan
40104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
41184.85.12.70NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_35a184-85-12-70.deploy.static.akamaitechnologies.comnan
4223.73.235.8EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_34a23-73-235-8.deploy.static.akamaitechnologies.comnan
43100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_33pool-100-37-135-2.nycmny.fios.verizon.netnan
4435.174.35.73AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_33ec2-35-174-35-73.compute-1.amazonaws.comnan
45104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
46104.18.82.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4754.242.20.247AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-242-20-247.compute-1.amazonaws.comnan
4899.84.114.90NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-90.ewr52.r.cloudfront.netnan
49184.87.68.204NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-87-68-204.deploy.static.akamaitechnologies.comnan
5023.73.228.188EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-73-228-188.deploy.static.akamaitechnologies.comnan
51104.21.6.127San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5223.38.170.24NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a23-38-170-24.deploy.static.akamaitechnologies.comnan
53104.16.8.138San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5434.207.4.240AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-34-207-4-240.compute-1.amazonaws.comnan
55104.18.79.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
56104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5799.84.114.35NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-35.ewr52.r.cloudfront.netnan
5854.236.76.250AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-236-76-250.compute-1.amazonaws.comnan
59140.174.12.80Union CityGeorgiaAS393259 Yottaa, Inc30291United Statestier_31nannan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website