Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
027528512040142021-04-1174.63.241.23Android
tierdomaincountregistrarname_serversorg
0tier_1storyowl.co1Communigal Communication Ltdns2.commonmx.comNone
1tier_1kalyanamandap.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
2tier_1telexfree.co1Communigal Communication Ltdns2.commonmx.comNone
3tier_1global-logistics.co1Communigal Communication Ltdns2.commonmx.comNone
4tier_1evanzhang.me1GoDaddy.com, LLCNoneNone
5tier_1bemember.me1GoDaddy.com, LLCNoneNone
6tier_1freedom-251.in1Dynadot LLCns1.commonmx.comNone
7tier_1voyeurcam.co1Communigal Communication Ltdns2.commonmx.comNone
8tier_1naarockers.cc1Domainshop LLCNS1.COMMONMX.COMNone
9tier_1stgeorges.co.in1Dynadot LLCns1.commonmx.comNone
10tier_2aristo-hag.com101Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
11tier_2btpnav.com821API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
12tier_2atnpx.com73GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
13tier_2click.expmediadirect.com64NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
14tier_2api.apptap.com64Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
15tier_2redirect.viglink.com64Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
16tier_2link.sylikes.com63MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
17tier_2rd.bizrate.com55NoneNoneNone
18tier_2rd.connexity.net53NoneNoneNone
19tier_2api.mplayit.com47Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
20tier_2ad.doubleclick.net34NoneNoneNone
21tier_2invictastores.com9GoDaddy.com, LLCDUKE.NS.CLOUDFLARE.COMNone
22tier_2trackyourmpg.com9NoneNoneNone
23tier_2rd.connexity.net_LOOP_18NoneNoneNone
24tier_2nizephoros-pom.com8Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGNone
25tier_2get.popplunder.com8NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
26tier_2trustedpush.com8NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
27tier_2win1.trustedpush.com8NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
28tier_2win2.trustedpush.com6NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
29tier_2btpnative.com51API GmbHNS1.DNSIMPLE.COMRegistrant of btpnative.com
30tier_3kbb.com55CSC CORPORATE DOMAINS, INC.PDNS164.ULTRADNS.BIZAutotrader.com
31tier_3robogarden.io17GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
32tier_3theory.com13CSC CORPORATE DOMAINS, INC.NS0.DNSMADEEASY.COMTheory LLC
33tier_3storystudio.sfgate.com12CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
34tier_3overstock.com10MarkMonitor, Inc.DNS1.P01.NSONE.NETOverstock.com, Inc - TMA606142
35tier_3rd.bizrate.com9NoneNoneNone
36tier_3invictastores.com_LOOP_19NoneNoneNone
37tier_3berettausa.com6Network Solutions, LLCNS1.AMERICANEAGLE.COMNone
38tier_3venus.com5GoDaddy.com, LLCNS0.DNSMADEEASY.COMVenus Fashion, Inc.
39tier_3m.placesiteb.xyz5Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
40tier_3overstock.com_LOOP_14NoneNoneNone
41tier_3win4.trustedpush.com4NAMECHEAP INCNS-1142.AWSDNS-14.ORGPrivacy service provided by Withheld for Privacy ehf
42tier_3m.gladplacespin.xyz3Epik LLCMARJORY.NS.CLOUDFLARE.COMAnonymize, Inc.
43tier_3filter.onwardclick.com2NAMECHEAP INCNS1.ENCONTEXT.COMPrivacy service provided by Withheld for Privacy ehf
44tier_3adameve.com2Network Solutions, LLCA1-75.AKAM.NETNone
45tier_3venus.com_LOOP_12NoneNoneNone
46tier_3beyourxfriend.com2GoDaddy.com, LLCNS0.DNSMADEEASY.COMNone
47tier_3win2.trustedpush.com2NameCheap, Inc.NS-1142.AWSDNS-14.ORGNone
48tier_3horny-honey.online1NAMECHEAP INCNS-19.AWSDNS-02.COMNone
49tier_3theory.com_LOOP_11NoneNoneNone
50tier_3equinoxadvertising.com_LOOP_11NoneNoneNone
51tier_3myhugesavings.com1Amazon Registrar, Inc.NS-1358.AWSDNS-41.ORGNone
52tier_3trk.careerbliss.com1GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
53tier_3search.discoverweb.com1GoDaddy.com, LLCNINA.NS.CLOUDFLARE.COMDomains By Proxy, LLC
54tier_3atnpx.com1GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
55tier_3wayfair.com1MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
56tier_3m.fastmapc.xyz1Sav.comLLCHUGH.NS.CLOUDFLARE.COMPrivacy Protection
57tier_3shop.diesel.com1BARBERO & Associates LtdNS3.OTB.NETREDACTED FOR PRIVACY
58tier_3aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGNone
59tier_3fanatics.com1MarkMonitor, Inc.A1-147.AKAM.NETFanatics Inc.
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_131nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_127nannan
2207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_119nannan
3207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_119nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_116nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
6104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
874.63.241.22DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1422-241-63-74.static.reverse.lstn.netnan
982.192.82.225AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_13nannan
10192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_39nannan
11209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_289nannan
12198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_264nannan
13192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_253rd.connexity.netnan
1434.197.67.232AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_247ec2-34-197-67-232.compute-1.amazonaws.comnan
1552.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_239ec2-52-205-177-114.compute-1.amazonaws.comnan
163.226.37.31AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_234ec2-3-226-37-31.compute-1.amazonaws.comnan
1734.225.128.119AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_230ec2-34-225-128-119.compute-1.amazonaws.comnan
18172.67.74.77San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_229nanTrue
1954.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-208-107-202.compute-1.amazonaws.comnan
2052.206.141.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_225ec2-52-206-141-190.compute-1.amazonaws.comnan
2152.206.108.38AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_223ec2-52-206-108-38.compute-1.amazonaws.comnan
22104.26.10.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_223nanTrue
23104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
24172.217.3.102WestburyNew YorkAS15169 Google LLC11590United Statestier_221lga34s18-in-f6.1e100.netnan
2599.84.114.90NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_219server-99-84-114-90.ewr52.r.cloudfront.netnan
2618.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_217ec2-18-235-67-128.compute-1.amazonaws.comnan
2734.207.43.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_217ec2-34-207-43-7.compute-1.amazonaws.comnan
2852.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_216ec2-52-72-29-7.compute-1.amazonaws.comnan
29204.44.79.214Los AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_212204.44.79.214.static.quadranet.comnan
3023.44.217.143NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_355a23-44-217-143.deploy.static.akamaitechnologies.comnan
31100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_326pool-100-37-135-2.nycmny.fios.verizon.netnan
32172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_312nanTrue
33104.77.221.88New York CityNew YorkAS16625 Akamai Technologies, Inc.10004United Statestier_310a104-77-221-88.deploy.static.akamaitechnologies.comnan
3423.73.239.49EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_310a23-73-239-49.deploy.static.akamaitechnologies.comnan
35192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_39nannan
3698.129.228.57DallasTexasAS33070 Rackspace Hosting75270United Statestier_36nannan
3723.73.224.199EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_36a23-73-224-199.deploy.static.akamaitechnologies.comnan
38151.101.0.200San FranciscoCaliforniaAS54113 Fastly94107United Statestier_36nanTrue
39104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
4023.73.235.8EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_34a23-73-235-8.deploy.static.akamaitechnologies.comnan
41104.18.80.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_34nanTrue
42104.18.79.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
43184.85.22.65NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_33a184-85-22-65.deploy.static.akamaitechnologies.comnan
44173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_32nannan
4523.73.247.78EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_32a23-73-247-78.deploy.static.akamaitechnologies.comnan
4645.33.8.244RichardsonTexasAS63949 Linode, LLC75080United Statestier_32li962-244.members.linode.comnan
4799.84.47.53NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-47-53.ewr52.r.cloudfront.netnan
48184.85.12.70NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-85-12-70.deploy.static.akamaitechnologies.comnan
49104.18.81.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5054.71.200.88BoardmanOregonAS16509 Amazon.com, Inc.97818United Statestier_31ec2-54-71-200-88.us-west-2.compute.amazonaws.comnan
51207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_31cbsmtp1.careerbliss.comnan
52172.67.144.251San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
53104.26.11.53San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5423.41.189.99NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-99.deploy.static.akamaitechnologies.comnan
55104.18.78.149San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
56104.17.8.188San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
5754.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-208-107-202.compute-1.amazonaws.comnan
58184.87.65.240NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-87-65-240.deploy.static.akamaitechnologies.comnan
5999.84.114.98NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-98.ewr52.r.cloudfront.netnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website