Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02412388050182021-04-0774.63.241.23Chrome
tierdomaincountregistrarname_serversorg
0tier_1teamice.us1Communigal Communication Ltdns2.commonmx.comNone
1tier_1girlystuff.info1Dynadot, LLCNS1.COMMONMX.COMNone
2tier_1uhmanoa.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1studiojimbo.io1Dynadot, LLCNS1.COMMONMX.COMNone
4tier_1786.name1NoneNoneNone
5tier_1misopan.net1DYNADOT, LLCNS1.COMMONMX.COMNone
6tier_1yume-baken.com1Communigal Communication LtdNS1.COMMONMX.COMNone
7tier_1editimage.org1GoDaddy.com, LLCNS1.COMMONMX.COMVirtua Drug Ltd
8tier_1aashagupta.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158839965
9tier_1iphone3g.info1Dynadot, LLCNS1.COMMONMX.COMNone
10tier_2click.expmediadirect.com123NoneNoneNone
11tier_2rqhere2.com122NoneNoneNone
12tier_2btpnav.com461API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
13tier_21496.rawlexi.com44GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
14tier_2americanlisted.com39ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_2rtbstream.com41API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
16tier_2api.apptap.com4Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
17tier_2rd.bizrate.com4MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
18tier_2rd.connexity.net4NoneNoneNone
19tier_2api.mplayit.com3Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
20tier_2redirect.viglink.com3Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
21tier_2link.sylikes.com3NoneNoneNone
22tier_2owletcare.com2GoDaddy.com, LLCNS41.DOMAINCONTROL.COMOwlet Baby Care
23tier_2btpnative.com21API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
24tier_2infopicked.com2NoneNoneNone
25tier_2nizephoros-pom.com2Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
26tier_2melanthios-ana.com2Amazon Registrar, Inc.NS-1354.AWSDNS-41.ORGNone
27tier_2rugab-ans.com2Amazon Registrar, Inc.NS-1165.AWSDNS-17.ORGNone
28tier_2clk.rtpdn12.com2NoneNoneNone
29tier_2filter.explorads.com2GoDaddy.com, LLCNS1.LINODE.COMDomains By Proxy, LLC
30tier_3youthandcare.info91NoneNoneNone
31tier_3us.tideri.com39united domains AGNS.UDAG.DENone
32tier_3thehealthlevel.info31NoneNoneNone
33tier_3americanlisted.com5ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
34tier_3owletcare.com_LOOP_12NoneNoneNone
35tier_3loyality-program.com2Amazon Registrar, Inc.NS-108.AWSDNS-13.COMNone
36tier_3search.discoverweb.com2GoDaddy.com, LLCNINA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
37tier_3promorepublic.com1Onlinenic IncLIA.NS.CLOUDFLARE.COMPromoRepublic Oy
38tier_3google.com_LOOP_11NoneNoneNone
39tier_3bing.com1MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
40tier_3eharmony.com1NoneNoneNone
41tier_3opticsplanet.com1GoDaddy.com, LLCNS1.ECENTRIA.COMECENTRIA IPH, LLC
42tier_3thredup.com1GoDaddy.com, LLCMATT.NS.CLOUDFLARE.COMThredUp Inc.
43tier_3welry.com1Amazon Registrar, Inc.NS-1079.AWSDNS-06.ORGNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_134nannan
1207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_123nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_119nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
5206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_112nannan
6104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
8185.107.56.200RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
974.63.241.23DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1223-241-63-74.static.reverse.lstn.netnan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2125nannan
11167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_2122nannan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_252nannan
13198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_244nannan
1435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_35240.61.209.35.bc.googleusercontent.comnan
15192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_28rd.bizrate.comnan
16192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_24rd.connexity.netnan
17100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_33pool-100-37-135-2.nycmny.fios.verizon.netnan
18209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_24nannan
1934.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-34-225-128-119.compute-1.amazonaws.comnan
2052.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-52-72-29-7.compute-1.amazonaws.comnan
21159.127.43.26WashingtonWashington, D.C.AS25751 Conversant, Inc.20045United Statestier_23nannan
2252.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-52-205-177-114.compute-1.amazonaws.comnan
2334.197.67.232AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-34-197-67-232.compute-1.amazonaws.comnan
2423.227.38.32OttawaOntarioAS13335 Cloudflare, Inc.K2PCanadatier_22myshopify.comTrue
25173.192.101.24DallasTexasAS36351 SoftLayer Technologies Inc.75270United Statestier_2218.65.c0ad.ip4.static.sl-reverse.comnan
2634.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-34-197-176-2.compute-1.amazonaws.comnan
27173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_22nannan
28185.170.102.1MiamiFloridaAS45028 Barefruit Ltd.33102United Statestier_22nannan
2952.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-52-206-141-190.compute-1.amazonaws.comnan
30172.67.167.55San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_350nanTrue
31104.21.11.199San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_341nanTrue
3235.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_339123.171.246.35.bc.googleusercontent.comnan
33104.21.75.98San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_316nanTrue
34172.67.220.94San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_315nanTrue
3535.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_35240.61.209.35.bc.googleusercontent.comnan
36100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_33pool-100-37-135-2.nycmny.fios.verizon.netnan
3734.192.40.54AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-34-192-40-54.compute-1.amazonaws.comnan
38104.21.95.133San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
39104.26.10.26San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
4013.107.22.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31nanTrue
41104.16.9.138San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
42152.195.32.168AshburnVirginiaAS15133 MCI Communications Services, Inc. d/b/a Verizon Business20147United Statestier_31nanTrue
43104.18.22.236San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
4454.236.76.250AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-236-76-250.compute-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website