Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02342378300162021-04-0974.63.241.23Chrome
tierdomaincountregistrarname_serversorg
0tier_1jkgschool.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
1tier_1maxo.pro1NoneNoneNone
2tier_1evanzhang.me1NoneNoneNone
3tier_1gaben.us1Communigal Communication Ltdns2.commonmx.comNone
4tier_1studiojimbo.io1NoneNoneNone
5tier_1la2tatcom.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159165625
6tier_1mooncake.us1Communigal Communication Ltdns2.commonmx.comNone
7tier_1l2s.cc1DYNADOT LLCNS1.COMMONMX.COMNone
8tier_1tophost.pro1NoneNoneNone
9tier_1verid.org1NoneNoneNone
10tier_2rqhere2.com104NoneNoneNone
11tier_2click.expmediadirect.com101NoneNoneNone
12tier_2btpnav.com451API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
13tier_21496.rawlexi.com39GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
14tier_2americanlisted.com35ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_29nl.es19NoneNoneNone
16tier_2newre-conversions.clickmeter.com19REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
17tier_2trk.jometer.com17Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
18tier_2api.l5srv.net14GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
19tier_2aristo-hag.com7Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
20tier_2clk.rtpdn12.com6NoneNoneNone
21tier_2rtbstream.com61API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
22tier_2ads35.adtelligent.com5DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
23tier_2dsp35.adtelligent.com5DANESCO TRADING LTDNS.ANYCASTNS1.ORGVertamedia,LLC
24tier_2aldb1.mysearch.space5NoneNoneNone
25tier_2externals-1953518744.us-east-1.elb.amazonaws.com5MarkMonitor, Inc.R1.AMAZONAWS.COMAmazon.com, Inc.
26tier_2search.snjsearch.com5GoDaddy.com, LLCNS73.DOMAINCONTROL.COMDomains By Proxy, LLC
27tier_2track.vcdc.com5Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
28tier_2click.appcast.io5NoneNoneNone
29tier_2whatjobs.com3123-Reg LimitedVIDA.NS.CLOUDFLARE.COMNone
30tier_3healthideal.club61NoneNoneNone
31tier_3healthyspirit.info28NoneNoneNone
32tier_3naturalsymud.club15NoneNoneNone
33tier_3us.tideri.com14united domains AGNS.UDAG.DENone
34tier_3upward.careers14GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
35tier_3bing.com5MarkMonitor, Inc.DNS1.P09.NSONE.NETMicrosoft Corporation
36tier_3americanlisted.com3ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
37tier_3click.appcast.io2NoneNoneNone
38tier_3ram21.proasdf.com2GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
39tier_3click.appcast.io_LOOP_12NoneNoneNone
40tier_3signup.finddreamjobs.com2GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
41tier_31.contentgate.uno1NoneNoneNone
42tier_3google.com_LOOP_11NoneNoneNone
43tier_3driverfixersoftware.com1TLDS L.L.C. d/b/a SRSPlusNINA.NS.CLOUDFLARE.COMNone
44tier_3opticsplanet.com1GoDaddy.com, LLCNS1.ECENTRIA.COMECENTRIA IPH, LLC
45tier_3rd.bizrate.com1MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
46tier_3search.discoverweb.com1GoDaddy.com, LLCNINA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
47tier_3higher-hire.com1Name.com, Inc.NS1GMZ.NAME.COMEverlong Media, LLC
48tier_3reebok.com1CSC CORPORATE DOMAINS, INC.NS1.NETNAMES.NETReebok International, Ltd.
49tier_3wayfair.com1MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
50tier_3saferealestatesearch.com1GoDaddy.com, LLCNS63.DOMAINCONTROL.COMDomains By Proxy, LLC
51tier_32.contentgate.uno1NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
1207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_124nannan
2207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
3206.221.176.184NewarkNew JerseyAS23470 ReliableSite.Net LLC07175United Statestier_117nannan
4207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_116nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
882.192.82.225AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_16nannan
937.48.65.150AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nannan
10167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_2104nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2103nannan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_252nannan
13198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_239nannan
1435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
1567.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_214nannan
1623.21.166.230AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-23-21-166-230.compute-1.amazonaws.comnan
1754.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_212ec2-54-235-205-204.compute-1.amazonaws.comnan
1899.84.114.53NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_28server-99-84-114-53.ewr52.r.cloudfront.netnan
1954.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-54-197-247-190.compute-1.amazonaws.comnan
2023.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-23-21-53-13.compute-1.amazonaws.comnan
21173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_26nannan
22192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31nannan
23209.205.202.42New York CityNew YorkAS55081 24 SHELLS10004United Statestier_25static-42-202-205-209.24shells.netnan
24209.205.202.43New York CityNew YorkAS55081 24 SHELLS10004United Statestier_25static-43-202-205-209.24shells.netnan
2535.162.164.74BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_25ec2-35-162-164-74.us-west-2.compute.amazonaws.comnan
2699.84.114.65NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_25server-99-84-114-65.ewr52.r.cloudfront.netnan
27178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nannan
28167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_25static.197.8.233.167.clients.your-server.denan
2934.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-34-207-43-7.compute-1.amazonaws.comnan
30104.21.59.182San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_337nanTrue
31172.67.182.64San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_324nanTrue
3235.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_314123.171.246.35.bc.googleusercontent.comnan
3367.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_314nannan
34104.21.30.32San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314nanTrue
35100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_314pool-100-37-135-2.nycmny.fios.verizon.netnan
36172.67.219.181San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_38nanTrue
37104.21.38.63San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_37nanTrue
38172.67.150.117San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
39204.79.197.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_33a-0001.a-msedge.netTrue
4035.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
4113.107.21.200RedmondWashingtonAS8068 Microsoft Corporation98052United Statestier_32nanTrue
42178.62.225.201AmsterdamNorth HollandAS14061 DigitalOcean, LLC1012Netherlandstier_32nannan
43162.243.10.151New York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_32nannan
44104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4552.3.4.129AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-3-4-129.compute-1.amazonaws.comnan
46104.21.83.108San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
47100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-100-25-52-1.compute-1.amazonaws.comnan
48152.195.32.168AshburnVirginiaAS15133 MCI Communications Services, Inc. d/b/a Verizon Business20147United Statestier_31nanTrue
49192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31nannan
50104.21.95.133San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5123.44.210.223EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-44-210-223.deploy.static.akamaitechnologies.comnan
5223.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-99.deploy.static.akamaitechnologies.comnan
53134.122.9.169CliftonNew JerseyAS14061 DigitalOcean, LLC07014United Statestier_31nannan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website