Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
01992026900102021-04-1474.63.241.23Safari
tierdomaincountregistrarname_serversorg
0tier_1asiancams365.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
1tier_1darksideofthetune.com1Domain Lifestyle, LLCNS1.COMMONMX.COMNone
2tier_1allmomboy.com1ABOVE.COM PTY LTD.NS1.COMMONMX.COMNone
3tier_1akktif.com1OldTownDomains.com LLCNS1.COMMONMX.COMNone
4tier_1abuadzhan.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
5tier_1brooklyning.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1craiglisttampa.com1SNAPNAMES 2, LLCNS1.COMMONMX.COMNone
7tier_1dggfd.com1NoneNoneNone
8tier_1elizabeth4idr10.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
9tier_1atlantisbio.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2rqhere2.com117NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
11tier_2click.expmediadirect.com116NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
12tier_21496.rawlexi.com28GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
13tier_2americanlisted.com28ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
14tier_2btpnav.com181API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
15tier_29nl.es13NoneNoneNone
16tier_2newre-conversions.clickmeter.com13REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
17tier_2click.appcast.io9101Domain GRS LtdNS-85.AWSDNS-10.COMNone
18tier_2ring.joveo.com6Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
19tier_2click.joveo.com4Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
20tier_2jobdiagnosis.com3GoDaddy.com, LLC10.SUCURIDNS.COMVHMnetwork LLC
21tier_2click.junmediadirect.com3NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
22tier_2us.tideri.com3united domains AGNS.UDAG.DENone
23tier_2trk.jometer.com3Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
24tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
25tier_2api.mplayit.com2Amazon Registrar, Inc.NS-1236.AWSDNS-26.ORGWhois Privacy Service
26tier_2redirect.viglink.com2Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
27tier_2link.sylikes.com2MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
28tier_2clk.rtpdn12.com2NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
29tier_2p.nexxt.com2Network Solutions, LLCNS21.WORLDNIC.COMNone
30tier_3thehealthcloud.club70NAMECHEAP INCmolly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
31tier_3yourhealthcall.club47NoneNoneNone
32tier_3us.tideri.com4united domains AGNS.UDAG.DENone
33tier_3click.joveo.com4Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
34tier_3homeadvisorpros.com3GoDaddy.com, LLCARYA.NS.CLOUDFLARE.COMService Magic Inc
35tier_3google.com3MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
36tier_3careerbuilder.com3CSC CORPORATE DOMAINS, INC.BROCK.CBJOBS.NETCareerBuilder, LLC
37tier_3signup.finddreamjobs.com2GoDaddy.com, LLCALEXIS.NS.CLOUDFLARE.COMFind Dream Jobs
38tier_3upward.careers2GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
39tier_3trk.careerbliss.com1GoDaddy.com, LLCNS10.DNSMADEEASY.COMDomains By Proxy, LLC
40tier_3s3.amazonaws.com1NoneNoneNone
41tier_3rd.bizrate.com1NoneNoneNone
42tier_3linkup.com1GoDaddy.com, LLCNS-102.AWSDNS-12.COMJobDig
43tier_3getstarjobs.getitcorporate.com1GoDaddy.com, LLCNS-CLOUD-E1.GOOGLEDOMAINS.COMGet It LLC
44tier_3rqhere2.com1NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
45tier_3monster.com1CSC CORPORATE DOMAINS, INC.NS1.TMPW.NETMonster Worldwide, Inc.
46tier_3jobleads.com1united domains AGCRUZ.NS.CLOUDFLARE.COMNone
47tier_3charterseniorliving.jobaline.com1GoDaddy.com, LLCNS-1232.AWSDNS-26.ORGJobaline Inc.
48tier_3us.jobtome.com1GoDaddy.com, LLCCHRIS.NS.CLOUDFLARE.COMNone
49tier_3ballarddesigns.com_LOOP_11NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
1207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
3207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_18nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_16nannan
874.63.241.19DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1319-241-63-74.static.reverse.lstn.netnan
9185.107.56.200RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_12nannan
10167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2116nannan
12198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_228nannan
1335.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_228240.61.209.35.bc.googleusercontent.comnan
14209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_218nannan
1523.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_29ec2-23-21-166-45.compute-1.amazonaws.comnan
1623.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_27ec2-23-21-53-13.compute-1.amazonaws.comnan
1754.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-54-235-205-204.compute-1.amazonaws.comnan
183.234.0.165AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-3-234-0-165.compute-1.amazonaws.comnan
1954.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-54-197-247-190.compute-1.amazonaws.comnan
2013.33.46.15NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_23server-13-33-46-15.ewr52.r.cloudfront.netnan
21192.124.249.12MenifeeCaliforniaAS30148 Sucuri92584United Statestier_23cloudproxy10012.sucuri.netTrue
22198.134.116.18New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_23nannan
2335.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_34123.171.246.35.bc.googleusercontent.comnan
24100.25.52.1AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-100-25-52-1.compute-1.amazonaws.comnan
25192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31rd.bizrate.comnan
26173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_23nannan
2799.84.114.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-107.ewr52.r.cloudfront.netnan
2852.205.177.114AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-52-205-177-114.compute-1.amazonaws.comnan
2913.33.46.77NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_22server-13-33-46-77.ewr52.r.cloudfront.netnan
30104.21.11.113San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_344nanTrue
31104.21.54.180San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_327nanTrue
32172.67.191.250San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_326nanTrue
33172.67.141.5San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_320nanTrue
3435.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_34123.171.246.35.bc.googleusercontent.comnan
35104.16.10.24San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
36100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.netnan
37172.217.10.100CliftonNew JerseyAS15169 Google LLC07015United Statestier_32lga34s15-in-f4.1e100.netnan
38104.17.47.14San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
3999.84.114.81NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-114-81.ewr52.r.cloudfront.netnan
4067.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_32nannan
4199.84.47.14NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_32server-99-84-47-14.ewr52.r.cloudfront.netnan
42172.217.10.132CliftonNew JerseyAS15169 Google LLC07015United Statestier_31lga34s16-in-f4.1e100.netnan
43207.38.44.116Los AngelesCaliforniaAS5693 Latisys-Irvine, LLC90009United Statestier_31cbsmtp1.careerbliss.comnan
4499.84.114.4NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-4.ewr52.r.cloudfront.netnan
4552.216.152.198AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
46192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31rd.bizrate.comnan
4735.241.55.51Kansas CityMissouriAS15169 Google LLC64121United Statestier_3151.55.241.35.bc.googleusercontent.comTrue
48167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_31nannan
4999.84.114.107NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-107.ewr52.r.cloudfront.netnan
5099.84.47.94NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-47-94.ewr52.r.cloudfront.netnan
51194.6.195.224HamburgHamburgAS39227 Corpex Internet GmbH20038Germanytier_31www.jobleads.denan
5218.233.183.34AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-18-233-183-34.compute-1.amazonaws.comnan
5399.84.47.36NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-47-36.ewr52.r.cloudfront.netnan
54130.211.38.206Kansas CityMissouriAS15169 Google LLC64121United Statestier_31206.38.211.130.bc.googleusercontent.comTrue

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website