Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02792779560162021-04-0774.63.241.23Safari
tierdomaincountregistrarname_serversorg
0tier_1teamice.us1Communigal Communication Ltdns2.commonmx.comNone
1tier_1girlystuff.info1Dynadot, LLCNS1.COMMONMX.COMNone
2tier_1uhmanoa.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
3tier_1studiojimbo.io1Dynadot, LLCNS1.COMMONMX.COMNone
4tier_1786.name1NoneNoneNone
5tier_1misopan.net1DYNADOT, LLCNS1.COMMONMX.COMNone
6tier_1yume-baken.com1Communigal Communication LtdNS1.COMMONMX.COMNone
7tier_1editimage.org1GoDaddy.com, LLCNS1.COMMONMX.COMVirtua Drug Ltd
8tier_1mooncake.us1Communigal Communication Ltdns2.commonmx.comNone
9tier_1aashagupta.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158839965
10tier_2click.expmediadirect.com138NoneNoneNone
11tier_2rqhere2.com138NoneNoneNone
12tier_2btpnav.com471API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
13tier_21496.rawlexi.com43GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
14tier_2americanlisted.com35ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_29nl.es16NoneNoneNone
16tier_2newre-conversions.clickmeter.com16REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
17tier_2trk.jometer.com15Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
18tier_2api.l5srv.net14GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
19tier_2nizephoros-pom.com7Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
20tier_2managerformula.com6NoneNoneNone
21tier_2click.appcast.io5101Domain GRS LtdNS-85.AWSDNS-10.COMNone
22tier_27587.rawlexi.com4GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
23tier_2affilynx.g2afse.com4GoDaddy.com, LLCNS-1393.AWSDNS-46.ORGAditec Solutions, UAB
24tier_2tracking.trkshark.cc4NoneNoneNone
25tier_2apptrk.space4NoneNoneNone
26tier_2joblift.com3INWX GmbH & Co. KGNS-CLOUD-E1.GOOGLEDOMAINS.COMREDACTED FOR PRIVACY
27tier_2click.appcast.io_LOOP_13NoneNoneNone
28tier_2api.apptap.com3Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
29tier_2redirect.viglink.com3Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
30tier_3clearhealthaspect.info61NoneNoneNone
31tier_3thehealthlevel.info36NoneNoneNone
32tier_3livingyoung.info25NoneNoneNone
33tier_3youthandcare.info16NoneNoneNone
34tier_3us.tideri.com15united domains AGNS.UDAG.DENone
35tier_3upward.careers14GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
36tier_3americanlisted.com8ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
37tier_3s3.amazonaws.com6MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
38tier_3apple.global-info.space3NoneNoneNone
39tier_3music.apple.com1CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
40tier_3jobs.dish.com1Network Solutions, LLCNS-01.DISH.COMDish Network LLC
41tier_3managerformula.com1NoneNoneNone
42tier_3robogarden.io1GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
43tier_3click.expmediadirect.com1NoneNoneNone
44tier_3socalhondadealers.com1DREAMHOSTNS1.DREAMHOST.COMProxy Protection LLC
45tier_3click.appcast.io1101Domain GRS LtdNS-85.AWSDNS-10.COMNone
46tier_3apple.service-care.space1NoneNoneNone
47tier_3linkedin.com1MarkMonitor, Inc.DNS1.P09.NSONE.NETLinkedIn Corporation
48tier_31496.rawlexi.com1GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
49tier_3joblift.com_LOOP_11NoneNoneNone
50tier_3eharmony.com1NoneNoneNone
51tier_3michaelkors.com1NOM-IQ Ltd dba Com LaudeA1-111.AKAM.NETMichael Kors, L.L.C.
52tier_3albeebaby.com_LOOP_11NoneNoneNone
53tier_3open.app.jobrapido.com_LOOP_11NoneNoneNone
54tier_3maurices.com_LOOP_11NoneNoneNone
55tier_3welry.com1Amazon Registrar, Inc.NS-1079.AWSDNS-06.ORGWhois Privacy Service
56tier_3signup.finddreamjobs.com1GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_132nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
3207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_121nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_119nannan
5206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_118nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
7104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
882.192.82.228AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_14nannan
9185.107.56.198RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_13nannan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2139nannan
11167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_2138nannan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_247nannan
13198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_31nannan
1435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_38240.61.209.35.bc.googleusercontent.comnan
1567.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_214nannan
1623.21.166.230AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_210ec2-23-21-166-230.compute-1.amazonaws.comnan
1754.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-54-235-205-204.compute-1.amazonaws.comnan
1823.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_28ec2-23-21-53-13.compute-1.amazonaws.comnan
1954.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-54-197-247-190.compute-1.amazonaws.comnan
2099.84.114.53NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_26server-99-84-114-53.ewr52.r.cloudfront.netnan
21192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_26rd.bizrate.comnan
22100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_36pool-100-37-135-2.nycmny.fios.verizon.netnan
2399.84.114.17NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_24server-99-84-114-17.ewr52.r.cloudfront.netnan
24212.32.252.81AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_24nannan
25212.32.249.98AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_24nannan
263.128.251.116HilliardOhioAS16509 Amazon.com, Inc.43026United Statestier_24ec2-3-128-251-116.us-east-2.compute.amazonaws.comnan
2734.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-34-207-43-7.compute-1.amazonaws.comnan
28172.232.19.138NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_24a172-232-19-138.deploy.static.akamaitechnologies.comnan
2935.190.64.22Kansas CityMissouriAS15169 Google LLC64121United Statestier_2322.64.190.35.bc.googleusercontent.comTrue
30104.21.60.64San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_341nanTrue
31104.21.75.98San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_327nanTrue
32172.67.192.183San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_320nanTrue
33104.21.94.161San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_318nanTrue
3435.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_315123.171.246.35.bc.googleusercontent.comnan
3567.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_314nannan
36104.21.11.199San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_313nanTrue
37172.67.220.94San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_39nanTrue
3835.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_38240.61.209.35.bc.googleusercontent.comnan
39172.67.138.17San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
40100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_36pool-100-37-135-2.nycmny.fios.verizon.netnan
41172.67.167.55San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
42104.21.78.145San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
4352.217.97.102AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4452.216.249.206AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4554.163.189.80AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-163-189-80.compute-1.amazonaws.comnan
46172.232.19.147NewarkNew JerseyAS20940 Akamai International B.V.07175United Statestier_31a172-232-19-147.deploy.static.akamaitechnologies.comnan
47104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
4835.174.35.73AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-35-174-35-73.compute-1.amazonaws.comnan
493.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-3-234-0-165.compute-1.amazonaws.comnan
5052.216.186.21AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
51104.21.77.6San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5213.107.42.14RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_31nanTrue
53198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_31nannan
54104.16.9.138San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
55184.85.16.53NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-85-16-53.deploy.static.akamaitechnologies.comnan
56107.23.69.42AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-107-23-69-42.compute-1.amazonaws.comnan
57104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5852.216.162.85AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website