Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02022016330162021-04-1574.63.241.23Safari
tierdomaincountregistrarname_serversorg
0tier_1wallpaperhdfree.in1Dynadot LLCns1.commonmx.comNone
1tier_1asiancams365.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
2tier_1kbc9.com1Anessia Inc.NS1.COMMONMX.COMNone
3tier_1allmomboy.com1ABOVE.COM PTY LTD.NS1.COMMONMX.COMNone
4tier_1akktif.com1OldTownDomains.com LLCNS1.COMMONMX.COMNone
5tier_1abuadzhan.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
6tier_1brooklyning.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
7tier_1craiglisttampa.com1Mark Barker IncorporatedNS1.COMMONMX.COMNone
8tier_1bicoholics.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158852663
9tier_1atlantisbio.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2rqhere2.com129NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
11tier_2click.expmediadirect.com123NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
12tier_21496.rawlexi.com20GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
13tier_2track.vcdc.com7Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
14tier_2clk.rtpdn12.com6NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
15tier_2click.junmediadirect.com3NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
16tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
17tier_2redirect.viglink.com2Amazon Registrar, Inc.NS1.VIGLINK.COMWhois Privacy Service
18tier_2link.sylikes.com2MarkMonitor, Inc.NS-1063.AWSDNS-04.ORGConnexity, Inc.
19tier_2rd.bizrate.com2MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
20tier_2rd.connexity.net2MarkMonitor, Inc.NS-1190.AWSDNS-20.ORGConnexity, Inc.
21tier_2rd.connexity.net_LOOP_12NoneNoneNone
22tier_2aristo-hag.com1Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
23tier_2clever-redirect.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
24tier_2tracker.clever-redirect.com1NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
25tier_2searchfor.org1Key-Systems GmbHBRENDA.NS.CLOUDFLARE.COM['Proof Labs UG (haftungsbeschraenkt)', 'REDACTED FOR PRIVACY']
26tier_2smartredirect.de1NoneNoneNone
27tier_2click.linksynergy.com1CSC CORPORATE DOMAINS, INC.DNS1.P09.NSONE.NETRakuten Marketing
28tier_2ad.atdmt.com1RegistrarSafe, LLCNS-1471.AWSDNS-55.ORGFacebook, Inc.
29tier_2ww2.siteplug.com1DOMAINPEOPLE, INC.NS-1263.AWSDNS-29.ORGREDACTED FOR PRIVACY
30tier_3organicpact.club39NameCheap, Inc.molly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
31tier_3fitnessagility.club35NAMECHEAP INCmolly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
32tier_3healthyeskimo.club30NoneNoneNone
33tier_3keytohealth.club25NoneNoneNone
34tier_3americanlisted.com19ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
35tier_3orvis.com1CSC CORPORATE DOMAINS, INC.EVAN.NS.CLOUDFLARE.COMThe Orvis Company, Inc
36tier_3ray-ban.com1REGISTER S.P.A.DNS1.P03.NSONE.NETLuxottica Group S.p.A.
37tier_3icus3.uft2bugay6.com1GoDaddy Online Services Cayman Islands LTDNS1.SURFDNS.ORGNone
38tier_3skechers.com_LOOP_11NoneNoneNone
39tier_3thomann.de1NoneNoneNone
40tier_3offer.alibaba.com1Alibaba Cloud Computing (Beijing) Co., Ltd.NS1.ALIBABADNS.COMNone
41tier_3blair.com_LOOP_11NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_123nannan
1207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
2207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_120nannan
3207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_119nannan
4104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_113nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
7104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
8185.107.56.198RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
974.63.241.23DallasTexasAS46475 Limestone Networks, Inc.75270United Statestier_1423-241-63-74.static.reverse.lstn.netnan
10167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_2129nannan
11198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2124nannan
12198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_220nannan
13167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_27static.197.8.233.167.clients.your-server.denan
14173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_27nannan
15100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.netnan
16192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_24rd.bizrate.comnan
17198.134.116.18New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_23nannan
18159.127.43.26WashingtonWashington, D.C.AS25751 Conversant, Inc.20045United Statestier_23nannan
1978.46.197.88NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_22static.88.197.46.78.clients.your-server.denan
20172.245.240.87ChicagoIllinoisAS36352 ColoCrossing60666United Statestier_31172-245-240-87-host.colocrossing.comnan
2154.84.4.127AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_22ec2-54-84-4-127.compute-1.amazonaws.comnan
22192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_22rd.connexity.netnan
2318.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-18-235-67-128.compute-1.amazonaws.comnan
24172.67.74.121San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_21nanTrue
25172.67.128.101San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_21nanTrue
2635.212.127.247WashingtonWashington, D.C.AS15169 Google LLC20045United Statestier_21247.127.212.35.bc.googleusercontent.comnan
2731.13.71.2New York CityNew YorkAS32934 Facebook, Inc.10004United Statestier_21edge-atlas-shv-01-lga3.facebook.comnan
28216.139.248.127AustinTexasAS32400 Hostway Services, Inc.78701United Statestier_21216-139-248-127.aus.us.siteprotect.comnan
293.226.37.31AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_21ec2-3-226-37-31.compute-1.amazonaws.comnan
30172.67.181.41San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_322nanTrue
31104.21.26.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_321nanTrue
32172.67.218.91San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_320nanTrue
3335.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_319240.61.209.35.bc.googleusercontent.comnan
34172.67.184.43San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_318nanTrue
35104.21.51.140San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_317nanTrue
36172.67.135.28San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_314nanTrue
37104.21.48.107San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_312nanTrue
38104.21.24.113San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_35nanTrue
39100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_32pool-100-37-135-2.nycmny.fios.verizon.netnan
40104.16.28.86San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_31nanTrue
41184.85.24.32NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a184-85-24-32.deploy.static.akamaitechnologies.comnan
42172.245.240.87ChicagoIllinoisAS36352 ColoCrossing60666United Statestier_31172-245-240-87-host.colocrossing.comnan
43212.204.75.161MunichBavariaAS8767 M-net Telekommunikations GmbH80331Germanytier_31www.thomann.denan
44104.102.131.56EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a104-102-131-56.deploy.static.akamaitechnologies.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website