Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
024824810990182021-04-2174.63.241.23Safari
tierdomaincountregistrarname_serversorg
0tier_1microcephaly.us1Communi Gal Communications Ltd.ns2.commonmx.comNone
1tier_1epayfaucets.com1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0159169997
2tier_1tsimokh.name1NoneNoneNone
3tier_1rissospacificos.com1GoDaddy.com, LLCNS1.COMMONMX.COMNone
4tier_1ecovillages.us1Communi Gal Communications Ltd.ns2.commonmx.comNone
5tier_1canon-support.us1Dynadot LLCns2.commonmx.comNone
6tier_1detox-cleanse.us1Communi Gal Communications Ltd.ns2.commonmx.comNone
7tier_1pecl.net1GoDaddy.com, LLCNS1.COMMONMX.COMNone
8tier_1styling.name1NoneNoneNone
9tier_1blatle.net1TUCOWS, INC.NS1.COMMONMX.COMContact Privacy Inc. Customer 0158496796
10tier_21496.rawlexi.com118GoDaddy Online Services Cayman Islands LTDNS-128.AWSDNS-16.COMNone
11tier_2americanlisted.com113ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
12tier_2click.expmediadirect.com64NoneNoneNone
13tier_29nl.es63NoneNoneNone
14tier_2newre-conversions.clickmeter.com63REGISTER S.P.A.NS-1498.AWSDNS-59.ORGREDACTED FOR PRIVACY
15tier_2trk.jometer.com63Amazon Registrar, Inc.NS-129.AWSDNS-16.COMWhois Privacy Service
16tier_2api.l5srv.net63GoDaddy.com, LLCNS53.DOMAINCONTROL.COMDomains By Proxy, LLC
17tier_2rqhere2.com63NoneNoneNone
18tier_2nizephoros-pom.com17Amazon Registrar, Inc.NS-1192.AWSDNS-21.ORGWhois Privacy Service
19tier_2managerformula.com16NoneNoneNone
20tier_2rd.centrumjobs.com7GoDaddy.com, LLCNS-1527.AWSDNS-62.ORGDomains By Proxy, LLC
21tier_2click.appcast.io7101Domain GRS LtdNS-85.AWSDNS-10.COMNone
22tier_2systems.job.com3GoDaddy Online Services Cayman Islands LTDCASS.NS.CLOUDFLARE.COMNone
23tier_2aristo-hag.com3Amazon Registrar, Inc.NS-1226.AWSDNS-25.ORGWhois Privacy Service
24tier_2rd.hpjalerts.com3GoDaddy.com, LLCNS-1342.AWSDNS-39.ORGDomains By Proxy, LLC
25tier_2click.appcast.io_LOOP_12NoneNoneNone
26tier_2api.apptap.com2Amazon Registrar, Inc.NS-1256.AWSDNS-29.ORGWhois Privacy Service
27tier_2noclick.connexity.com2MarkMonitor, Inc.NS-1235.AWSDNS-26.ORGConnexity, Inc.
28tier_2rd.bizrate.com2NoneNoneNone
29tier_2rd.connexity.net2MarkMonitor Inc.NS-1190.AWSDNS-20.ORGNone
30tier_3upward.careers63GoDaddy.com, LLCns21.domaincontrol.comDomains By Proxy, LLC
31tier_3peakprestige.club63NoneNoneNone
32tier_3google.com38MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
33tier_3s3.amazonaws.com17NoneNoneNone
34tier_3neuvoo.com6MarkMonitor Inc.NS-1302.AWSDNS-34.ORGNone
35tier_3americanlisted.com6ilait ABNS1.TELECOM3.NETIntegration 3 Group AB
36tier_3findatruckerjob.com3GoDaddy.com, LLCNS63.DOMAINCONTROL.COMDomains By Proxy, LLC
37tier_3wayfair.com2MarkMonitor Inc.A1-100.AKAM.NETNone
38tier_3rd.bizrate.com1NoneNoneNone
39tier_3click.appcast.io_LOOP_11NoneNoneNone
40tier_3rd.hpjalerts.com1GoDaddy.com, LLCNS-1342.AWSDNS-39.ORGDomains By Proxy, LLC
41tier_3vitalydesign.com1GoDaddy.com, LLCNS11.DOMAINCONTROL.COMVitaly Design Ltd.
42tier_3amazon.com1NoneNoneNone
43tier_3us.tideri.com1united domains AGNS.UDAG.DENone
ipcityregionorgpostalcountry_nametiercounthostnameanycast
0207.244.67.215WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_131nannan
1207.244.67.216WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_128nannan
2207.244.67.214WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_125nannan
3207.244.67.218WashingtonWashington, D.C.AS30633 Leaseweb USA, Inc.20045United Statestier_122nannan
4104.243.45.178New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_114nannan
5104.243.45.179New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
6206.221.176.184New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_112nannan
7104.243.45.190New York CityNew YorkAS23470 ReliableSite.Net LLC10004United Statestier_111nannan
882.192.82.227AmsterdamNorth HollandAS60781 LeaseWeb Netherlands B.V.1012Netherlandstier_15nannan
9185.107.56.198RotterdamSouth HollandAS43350 NForce Entertainment B.V.3012Netherlandstier_14nannan
10198.54.112.216San JoseCaliforniaAS22612 Namecheap, Inc.95103United Statestier_2118nannan
1135.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_36240.61.209.35.bc.googleusercontent.comnan
12198.134.116.30New York CityNew YorkAS27257 Webair Internet Development Company Inc.10013United Statestier_264nannan
1367.227.173.37LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_263nannan
14167.99.3.175North BergenNew JerseyAS14061 DigitalOcean, LLC07047United Statestier_263nannan
1554.197.247.190AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_234ec2-54-197-247-190.compute-1.amazonaws.comnan
1654.235.205.204AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_232ec2-54-235-205-204.compute-1.amazonaws.comnan
1723.21.53.13AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_231ec2-23-21-53-13.compute-1.amazonaws.comnan
1823.21.166.45AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_229ec2-23-21-166-45.compute-1.amazonaws.comnan
1999.84.126.52NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_218server-99-84-126-52.ewr52.r.cloudfront.netnan
2099.84.126.65NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_216server-99-84-126-65.ewr52.r.cloudfront.netnan
2199.84.126.24NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_214server-99-84-126-24.ewr52.r.cloudfront.netnan
2299.84.126.63NewarkNew JerseyAS16509 Amazon.com, Inc.07175United Statestier_214server-99-84-126-63.ewr52.r.cloudfront.netnan
2334.197.176.2AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-34-197-176-2.compute-1.amazonaws.comnan
2418.235.67.128AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_26ec2-18-235-67-128.compute-1.amazonaws.comnan
2552.72.29.7AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_25ec2-52-72-29-7.compute-1.amazonaws.comnan
2654.208.107.202AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_24ec2-54-208-107-202.compute-1.amazonaws.comnan
27209.15.13.136TorontoOntarioAS13768 Aptum TechnologiesM5NCanadatier_24nannan
2823.200.0.5EdisonNew JerseyAS20940 Akamai International B.V.08817United Statestier_24a23-200-0-5.deploy.static.akamaitechnologies.comnan
2952.203.101.113AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_23ec2-52-203-101-113.compute-1.amazonaws.comnan
3067.227.172.40LansingMichiganAS32244 Liquid Web, L.L.C48901United Statestier_363nannan
31172.67.134.113San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_334nanTrue
32104.21.25.179San FranciscoCaliforniaAS13335 Cloudflare, Inc.94107United Statestier_329nanTrue
33172.217.12.132CliftonNew JerseyAS15169 Google LLC07015United Statestier_39lga34s19-in-f4.1e100.netnan
34172.217.11.36New York CityNew YorkAS15169 Google LLC10004United Statestier_37lga25s61-in-f4.1e100.netnan
35172.217.165.132Los AngelesCaliforniaAS15169 Google LLC90009United Statestier_37lax30s03-in-f4.1e100.netnan
3635.209.61.240Council BluffsIowaAS15169 Google LLC51502United Statestier_36240.61.209.35.bc.googleusercontent.comnan
37172.217.10.228CliftonNew JerseyAS15169 Google LLC07015United Statestier_35lga25s59-in-f4.1e100.netnan
38172.217.7.4Clinton CornersNew YorkAS15169 Google LLC12514United Statestier_34lga25s56-in-f4.1e100.netnan
39172.217.10.100CliftonNew JerseyAS15169 Google LLC07015United Statestier_33lga34s15-in-f4.1e100.netnan
40142.250.64.68WestburyNew YorkAS15169 Google LLC11590United Statestier_33lga34s30-in-f4.1e100.netnan
4154.242.20.247AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-54-242-20-247.compute-1.amazonaws.comnan
4252.216.154.46AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4352.217.83.70AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4452.217.100.190AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4552.216.227.115AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4652.217.162.248AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
4723.43.253.154NewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_32a23-43-253-154.deploy.static.akamaitechnologies.comnan
4852.21.31.105AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-52-21-31-105.compute-1.amazonaws.comnan
4954.144.219.72AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_32ec2-54-144-219-72.compute-1.amazonaws.comnan
5052.217.202.56AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_32s3-1.amazonaws.comnan
5152.216.178.181AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5254.163.119.112AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-54-163-119-112.compute-1.amazonaws.comnan
53192.138.218.207SeattleWashingtonAS14332 Connexity, Inc.98111United Statestier_31rd.bizrate.comnan
54100.37.135.2New York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_31pool-100-37-135-2.nycmny.fios.verizon.netnan
5554.231.40.226AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5652.216.245.254AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan
5752.22.57.118AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-52-22-57-118.compute-1.amazonaws.comnan
5834.196.177.100AshburnVirginiaAS14618 Amazon.com, Inc.20149United Statestier_31ec2-34-196-177-100.compute-1.amazonaws.comnan
5952.216.141.30AshburnVirginiaAS16509 Amazon.com, Inc.20149United Statestier_31s3-1.amazonaws.comnan

Aggregated redirection graph of domains located on current IP address.

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website