Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
02512518610152021-04-1774.63.241.23Safari
tierdomaincountregistrarname_serversorg
0tier_1serviciosjr.co1GoDaddy.com, LLCns2.commonmx.comNone
1tier_1100mdollarclub.co1Dynadot LLCns2.commonmx.comNone
2tier_1tpremium.me1Dynadot, LLCNoneNone
3tier_1abuadzhan.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1englishfluency.co1GoDaddy.com, LLCns2.commonmx.comNone
5tier_152stu.me1Dynadot, LLCNoneNone
6tier_1beritbart.com1ABOVE.COM PTY LTD.NS1.COMMONMX.COMNone
7tier_1rebell.co1GoDaddy.com, LLCns2.commonmx.comNone
8tier_1tcfs.co.in1Dynadot LLCns1.commonmx.comNone
9tier_1basicschoolnews.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
10tier_2rqhere2.com149NAMECHEAP INCJEROME.NS.CLOUDFLARE.COMPrivacy service provided by Withheld for Privacy ehf
11tier_2click.expmediadirect.com147NAMECHEAP INCNS1.LINODE.COMPrivacy service provided by Withheld for Privacy ehf
12tier_2btpnav.com311API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
13tier_21496.rawlexi.com24GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
14tier_2americanlisted.com20ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
15tier_29nl.es8NoneNoneNone
16tier_2newre-conversions.clickmeter.com8REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
17tier_2track.vcdc.com6Key-Systems GmbHGUY.NS.CLOUDFLARE.COMc/o whoisproxy.com
18tier_2aristo-hag.com6Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
19tier_2clk.rtpdn12.com5NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
20tier_2atnpx.com5GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMDomains By Proxy, LLC
21tier_2api.apptap.com4Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
22tier_2rd.bizrate.com4MarkMonitor, Inc.NS-1189.AWSDNS-20.ORGMeredith Corporation
23tier_2rd.connexity.net4NoneNoneNone
24tier_2trk.jometer.com3Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
25tier_2api.l5srv.net3GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
26tier_2rtbstream.com31API GmbHNS1.DNSIMPLE.COMRegistrant of rtbstream.com
27tier_2nizephoros-pom.com3Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
28tier_2filter.explorads.com3GoDaddy.com, LLCNS1.LINODE.COMDomains By Proxy, LLC
29tier_2click.expmediadirect.com_LOOP_13NoneNoneNone
30tier_3helpsense.club76NAMECHEAP INCmolly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
31tier_3curespectrum.club73NAMECHEAP INCmolly.ns.cloudflare.comPrivacy service provided by Withheld for Privacy ehf
32tier_3us.tideri.com12united domains AGNS.UDAG.DENone
33tier_3robogarden.io5GoDaddy.com, LLCBECKY.NS.CLOUDFLARE.COMNone
34tier_3upward.careers3GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
35tier_3managerformula.com3NAMECHEAP INCDNS1.REGISTRAR-SERVERS.COMPrivacy service provided by Withheld for Privacy ehf
36tier_3americanlisted.com3ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
37tier_3click.joveo.com3Go Canada Domains, LLCNS-1256.AWSDNS-29.ORGDomains By Proxy, LLC
38tier_3homeadvisorpros.com2GoDaddy.com, LLCARYA.NS.CLOUDFLARE.COMService Magic Inc
39tier_3music.apple.com2CSC CORPORATE DOMAINS, INC.A.NS.APPLE.COMApple Inc.
40tier_3wayfair.com2MarkMonitor, Inc.A1-100.AKAM.NETWayfair, LLC
41tier_3stateandliberty.com2GoDaddy.com, LLCNS55.DOMAINCONTROL.COMDomains By Proxy, LLC
42tier_3macys.com1Network Solutions, LLCA1-135.AKAM.NETMacy's Systems and Technology, Inc.
43tier_3btpnav.com11API GmbHNS1.DNSIMPLE.COMRegistrant of btpnav.com
44tier_3tracking.s24.com1GANDI SASNS-1158.AWSDNS-16.ORGNone
45tier_3citypass.com_LOOP_11NoneNoneNone
46tier_3google.com_LOOP_11NoneNoneNone
47tier_3thredup.com_LOOP_11NoneNoneNone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_129nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
2207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_126nannan
3207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_123nannan
4104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
5206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
6104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_110nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_19nannan
8185.107.56.198RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_17nannan
982.192.82.228AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
10198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_2150nannan
11167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_2149nannan
12209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_31nannan
13198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_224nannan
1435.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
15192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_26rd.bizrate.comnan
16167.233.8.197NürnbergBavariaAS24940 Hetzner Online GmbH90402Germanytier_26static.197.8.233.167.clients.your-server.denan
1734.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-34-197-176-2.compute-1.amazonaws.comnan
18173.239.53.32New York CityNew YorkAS27257 Webair Internet Development Company Inc.10004United Statestier_25nannan
1923.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-23-21-53-13.compute-1.amazonaws.comnan
203.224.109.140AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-3-224-109-140.compute-1.amazonaws.comnan
21192.138.218.139SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_24rd.connexity.netnan
2254.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-54-197-247-190.compute-1.amazonaws.comnan
2323.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-23-21-166-45.compute-1.amazonaws.comnan
24209.132.243.15Los AngelesCaliforniaAS7296 Alchemy Communications, Inc.90009United Statestier_24nannan
25100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_35pool-100-37-135-2.nycmny.fios.verizon.netnan
2667.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_23nannan
2754.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-54-235-205-204.compute-1.amazonaws.comnan
2854.84.4.127AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-54-84-4-127.compute-1.amazonaws.comnan
29159.127.43.26WashingtonWashington, D.C.AS25751 Conversant, Inc.20045United Statestier_23nannan
30104.21.71.138San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_348nanTrue
31172.67.179.21San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_339nanTrue
32104.21.35.195San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_337nanTrue
33172.67.145.102San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_325nanTrue
3435.246.171.123Frankfurt am MainHesseAS15169 Google LLC60311Germanytier_312123.171.246.35.bc.googleusercontent.comnan
35100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_35pool-100-37-135-2.nycmny.fios.verizon.netnan
3667.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_33nannan
3723.200.0.41EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_33a23-200-0-41.deploy.static.akamaitechnologies.comnan
3835.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_33240.61.209.35.bc.googleusercontent.comnan
39104.21.80.8San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_33nanTrue
40104.16.11.24San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
41172.67.172.143San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_32nanTrue
4223.227.38.32OttawaOntarioAS13335 Cloudflare, Inc.K2PCanadatier_32myshopify.comTrue
4323.41.189.63NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-41-189-63.deploy.static.akamaitechnologies.comnan
4413.225.222.112New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_31server-13-225-222-112.jfk51.r.cloudfront.netnan
4523.43.253.154NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_31a23-43-253-154.deploy.static.akamaitechnologies.comnan
46209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_31nannan
475.11.50.201Frankfurt am MainHesseAS47215 Filoo GmbH60311Germanytier_315-11-50-201.reverse.cust.as47215.netnan
4813.225.222.33New York CityNew YorkAS16509 Amazon.com, Inc.10004United Statestier_31server-13-225-222-33.jfk51.r.cloudfront.netnan
4999.84.114.67NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_31server-99-84-114-67.ewr52.r.cloudfront.netnan
5023.41.168.201EdisonNew JerseyAS16625 Akamai Technologies, Inc.08817United Statestier_31a23-41-168-201.deploy.static.akamaitechnologies.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website