Malware Discoverer Homepage.

Malware Discoverer Github Page (not maintained since 2022-07-28).

Daily Threat Intelligence Report¶

Our automated systems crawls large number of domains every day to discover URL redirections, malicious final landing sites, and malvertizing campaigns.

This report contains following information.

  1. Summary statistics (number of domains crawled, date, on what IP and with what device)
  2. Top 40 discovered domain, sorted by occurrence
  3. Top 40 discovered IP, sorted by occurrence
  4. Consolidated redirection paths
    1. green: tier one domain (what a user clicks)
    2. yellow: tier two domain (intermediate servers)
    3. red: tier three domain (what a user sees in the end)
  5. Consolidated screenshots of final landing sites

Content Warning: Some domain names and screenshots contain material that may be harmful or traumatizing to some audiences.

  num_domain num_links num_full_url num_safebrowsing_malicious num_vt_malicious date ip user_agent
0 247 243 628 0 0 2023-01-21 207.244.67.215 android
  tier domain count registrar name_servers org
0 tier_1 adulttvlive.com 1 Godomaingo.com LLC NS1.COMMONMX.COM None
1 tier_1 ivanbuilt.com 1 Domainsoftheworld.net LLC NS1.COMMONMX.COM None
2 tier_1 fullhizmet.com 1 GoDaddy.com, LLC NS1.COMMONMX.COM Domains By Proxy, LLC
3 tier_1 pa-mhd.biz 1 DYNADOT LLC ns1.commonmx.com None
4 tier_1 alltile.us 1 CommuniGal Communication Ltd. ns1.commonmx.com None
5 tier_1 skcarwash.com 1 TUCOWS, INC. NS1.COMMONMX.COM Contact Privacy Inc. Customer 0160999465
6 tier_1 dynobusrex.com 1 Key-Systems GmbH NS1.COMMONMX.COM REDACTED FOR PRIVACY
7 tier_1 blogsalbum.com 1 Domaingazelle.com LLC NS1.MYTRAFFICMANAGEMENT.COM None
8 tier_1 merdadolibre.com 1 DYNADOT, LLC NS1.COMMONMX.COM None
9 tier_1 citytrump.com 1 DYNADOT, LLC NS1.COMMONMX.COM None
10 tier_1 ecigscomparedreviewed.com 1 PortlandNames.com LLC NS1.MYTRAFFICMANAGEMENT.COM None
11 tier_1 leatrend.com 1 GoDaddy.com, LLC NS1.COMMONMX.COM Domains By Proxy, LLC
12 tier_1 ikincielbilgisayar.co 1 GoDaddy.com, LLC ns1.commonmx.com Domains By Proxy, LLC
13 tier_1 shambhalareiki.com 1 GoDaddy.com, LLC NS1.COMMONMX.COM Domains By Proxy, LLC
14 tier_1 mandoplayer.com 1 SNAPNAMES 10, LLC NS1.COMMONMX.COM None
15 tier_1 maracas915.com 1 Key-Systems GmbH NS1.COMMONMX.COM REDACTED FOR PRIVACY
16 tier_1 agnetismiracle.com 1 SNAPNAMES 68, LLC NS1.COMMONMX.COM None
17 tier_1 tamilyogii.com 1 TUCOWS, INC. NS1.COMMONMX.COM Contact Privacy Inc. Customer 0158515438
18 tier_1 teamonesoft.com 1 DropFall.com, LLC NS1.MYTRAFFICMANAGEMENT.COM None
19 tier_1 gahoopla.com 1 Key-Systems GmbH NS1.COMMONMX.COM REDACTED FOR PRIVACY
20 tier_1 nerdstuff.us 1 CommuniGal Communication Ltd. ns1.commonmx.com None
21 tier_1 quailrunlodge.com 1 EPAG DOMAINSERVICES GmbH NS1.COMMONMX.COM Not Disclosed
22 tier_1 jsautomobiles.com 1 Domainnovations, LLC NS1.COMMONMX.COM None
23 tier_1 odevtr.com 1 Sliceofheaven Domains, LLC NS1.MYTRAFFICMANAGEMENT.COM None
24 tier_1 tianyue658.com 1 Name Connection Area LLC NS1.MYTRAFFICMANAGEMENT.COM None
25 tier_1 mobiruby.com 1 GoDaddy.com, LLC NS1.COMMONMX.COM Domains By Proxy, LLC
26 tier_1 ghesports.com 1 TurnCommerce, Inc. DBA NameBright.com NSG1.NAMEBRIGHTDNS.COM HugeDomains.com
27 tier_1 shooter.us 1 CommuniGal Communication Ltd. ns1.commonmx.com None
28 tier_1 writescript.in 1 Key-Systems GmbH ns1.commonmx.com None
29 tier_1 indosoletw.com 1 Your Domain LLC NS1.MILESMX.COM None
30 tier_1 geotiling.com 1 Eranet International Limited NS1.TAOA.COM None
31 tier_1 ivanturetravels.com 1 NamePal.com #8027, LLC NS1.COMMONMX.COM None
32 tier_1 mayortw.com 1 ! #1 Host China, LLC NS1.COMMONMX.COM None
33 tier_1 johnkyffin.com 1 SNAPNAMES 45, LLC NS1.COMMONMX.COM None
34 tier_1 rocoto.us 1 CommuniGal Communication Ltd. ns1.commonmx.com None
35 tier_1 educazionecinofilavallebresciana.com 1 Register.com, Inc. NS1.COMMONMX.COM None
36 tier_1 gitlearn.com 1 TurnCommerce, Inc. DBA NameBright.com NSG1.NAMEBRIGHTDNS.COM HugeDomains.com
37 tier_1 bankexamtutor.com 1 DropJump.com, LLC NS1.COMMONMX.COM None
38 tier_1 haylazadam50.com 1 Key-Systems GmbH NS1.COMMONMX.COM REDACTED FOR PRIVACY
39 tier_1 jrafxo.com 1 GoServeYourDomain.com LLC NS1.COMMONMX.COM None
40 tier_2 btpnative.com 29 1API GmbH NS1.DNSIMPLE.COM REDACTED FOR PRIVACY
41 tier_2 mybettermb.com 29 NAMECHEAP INC NS10.DIGICERTDNS.COM Privacy service provided by Withheld for Privacy ehf
42 tier_2 miupqssp.com 27 NAMECHEAP INC NS-1132.AWSDNS-13.ORG Privacy service provided by Withheld for Privacy ehf
43 tier_2 redirects.tradedoubler.com 27 OVH, SAS NS-1359.AWSDNS-41.ORG TradeDoubler AB
44 tier_2 groceries.morrisons.com 27 NOM-IQ Ltd dba Com Laude NS0.DEMYSDNS.NET Wm Morrison Supermarkets PLC
45 tier_2 morrisons.queue-it.net 27 Instra Corporation Pty Ltd. NS-1175.AWSDNS-18.ORG REDACTED FOR PRIVACY
46 tier_2 p274639.mybettermb.com 25 NAMECHEAP INC NS10.DIGICERTDNS.COM Privacy service provided by Withheld for Privacy ehf
47 tier_2 vipestores.com 18 NAMECHEAP INC EVAN.NS.CLOUDFLARE.COM Privacy service provided by Withheld for Privacy ehf
48 tier_2 clkuk.tradedoubler.com 18 OVH, SAS NS-1359.AWSDNS-41.ORG TradeDoubler AB
49 tier_2 track.flexlinkspro.com 9 GoDaddy.com, LLC DARL.NS.CLOUDFLARE.COM Domains By Proxy, LLC
50 tier_2 clk.tradedoubler.com 9 OVH, SAS NS-1359.AWSDNS-41.ORG TradeDoubler AB
51 tier_2 qvikar.com 6 Sea Wasp, LLC NS2789.HOSTGATOR.COM Jewella Privacy LLC Privacy ID# 1016679
52 tier_2 p185689.mybettermb.com 4 NAMECHEAP INC NS10.DIGICERTDNS.COM Privacy service provided by Withheld for Privacy ehf
53 tier_2 ww2.affinity.net 4 DOMAINPEOPLE, INC. NS-1183.AWSDNS-19.ORG WhoisProtector Inc.
54 tier_2 beta.mybettermb.com 4 NAMECHEAP INC NS10.DIGICERTDNS.COM Privacy service provided by Withheld for Privacy ehf
55 tier_2 cj.dotomi.com 3 GoDaddy.com, LLC ASIA9.AKAM.NET Domains By Proxy, LLC
56 tier_2 www.emjcd.com 3 MarkMonitor, Inc. ASIA9.AKAM.NET Conversant, Inc.
57 tier_2 11165151.searchiqnet.com 2 GoDaddy.com, LLC NS57.DOMAINCONTROL.COM Domains By Proxy, LLC
58 tier_2 kky.apwk2.top 2 Eranet International Limited ns1.taoa.com FeiZhongBo
59 tier_2 1496.aphition.com 2 GoDaddy Online Services Cayman Islands Ltd. NS11.CONSTELLIX.COM None
60 tier_2 www.americanlisted.com 2 ilait AB NS1.TELECOM3.NET Integration 3 Group AB
61 tier_2 click.appcast.io 2 https://www.101domain.com/ ns-1093.awsdns-08.org None
62 tier_2 joblift.com 2 INWX GmbH NS-CLOUD-E1.GOOGLEDOMAINS.COM REDACTED FOR PRIVACY
63 tier_2 www.indeed.com 2 MarkMonitor, Inc. DNS1.P01.NSONE.NET Indeed, Inc
64 tier_2 us.conv.indeed.com 2 MarkMonitor, Inc. DNS1.P01.NSONE.NET Indeed, Inc
65 tier_2 ww1.adulttvlive.com 1 Godomaingo.com LLC NS1.COMMONMX.COM None
66 tier_2 ww1.fullhizmet.com 1 GoDaddy.com, LLC NS1.COMMONMX.COM Domains By Proxy, LLC
67 tier_2 ww1.alltile.us 1 CommuniGal Communication Ltd. ns1.commonmx.com None
68 tier_2 ww1.skcarwash.com 1 TUCOWS, INC. NS1.COMMONMX.COM Contact Privacy Inc. Customer 0160999465
69 tier_2 ww1.merdadolibre.com 1 DYNADOT, LLC NS1.COMMONMX.COM None
70 tier_2 ww1.citytrump.com 1 DYNADOT, LLC NS1.COMMONMX.COM None
71 tier_2 ww1.leatrend.com 1 GoDaddy.com, LLC NS1.COMMONMX.COM Domains By Proxy, LLC
72 tier_2 ww1.ikincielbilgisayar.co 1 GoDaddy.com, LLC ns1.commonmx.com Domains By Proxy, LLC
73 tier_2 ww1.shambhalareiki.com 1 GoDaddy.com, LLC NS1.COMMONMX.COM Domains By Proxy, LLC
74 tier_2 ww1.mandoplayer.com 1 SNAPNAMES 10, LLC NS1.COMMONMX.COM None
75 tier_2 ww1.maracas915.com 1 Key-Systems GmbH NS1.COMMONMX.COM REDACTED FOR PRIVACY
76 tier_2 ww1.tamilyogii.com 1 TUCOWS, INC. NS1.COMMONMX.COM Contact Privacy Inc. Customer 0158515438
77 tier_2 ww1.gahoopla.com 1 Key-Systems GmbH NS1.COMMONMX.COM REDACTED FOR PRIVACY
78 tier_2 ww1.nerdstuff.us 1 CommuniGal Communication Ltd. ns1.commonmx.com None
79 tier_2 c.pageprotect.net 1 GoDaddy.com, LLC NS75.DOMAINCONTROL.COM Domains By Proxy, LLC
80 tier_3 iyfbodn.com 66 PDR Ltd. d/b/a PublicDomainRegistry.com NS1.NSRESOLUTION.COM Privacy Protect, LLC (PrivacyProtect.org)
81 tier_3 groceries.morrisons.com_LOOP_1 27 None None None
82 tier_3 www.hugedomains.com 7 GoDaddy.com, LLC CHUCK.NS.CLOUDFLARE.COM Domains By Proxy, LLC
83 tier_3 www.clkmg.com 6 GoDaddy.com, LLC NS1.SOFTLAYER.COM None
84 tier_3 dc7.aipo64.top 2 Eranet International Limited ns1.taoa.com FeiZhongBo
85 tier_3 www.indeed.com_LOOP_1 2 None None None
86 tier_3 www.samsung.com 1 Whois Corp. DNS-AWSKR1.SAMSUNG.COM Samsung Electronics CO., Ltd
87 tier_3 amiclubwear.com 1 GoDaddy.com, LLC NS-1064.AWSDNS-05.ORG None
88 tier_3 www.hertz.com 1 MarkMonitor, Inc. DNS4.HERTZ.COM The Hertz Corporation
89 tier_3 www.transunion.com 1 CSC CORPORATE DOMAINS, INC. PDNS1.CSCDNS.NET Trans Union LLC
90 tier_3 www.myheritage.com 1 GoDaddy.com, LLC DNS1.P07.NSONE.NET None
91 tier_3 track.vcdc.com 1 Key-Systems GmbH GUY.NS.CLOUDFLARE.COM c/o whoisproxy.com
92 tier_3 www.tracfone.com 1 MarkMonitor, Inc. SDNS26.ULTRADNS.BIZ Verizon Trademark Services LLC
93 tier_3 www.amazon.com 1 MarkMonitor Inc. NS1.P31.DYNECT.NET None
94 tier_3 www.bodybuilding.com 1 MarkMonitor, Inc. NS1.BODYBUILDING.COM Vitalize, LLC
95 tier_3 88hebing.com 1 DYNADOT, LLC NS1.DYNA-NS.NET None
  ip hostname city region org postal country_name isEU tier count anycast
0 45.79.47.151 li1146-151.members.linode.com Richardson Texas AS63949 Akamai Technologies, Inc. 75080 United States False tier_1 17 nan
1 37.48.65.152 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 15 nan
2 37.48.65.154 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 10 nan
3 37.48.65.151 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 10 nan
4 37.48.65.150 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 10 nan
5 37.48.65.153 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 8 nan
6 37.48.65.149 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 7 nan
7 81.171.22.7 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 7 nan
8 81.171.22.4 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 7 nan
9 81.171.22.6 nan Amsterdam North Holland AS60781 LeaseWeb Netherlands B.V. 1012 Netherlands True tier_1 6 nan
10 199.59.243.222 nan Tampa Florida AS16509 Amazon.com, Inc. 33609 United States False tier_2 66 True
11 52.116.53.155 9b.35.7434.ip4.static.sl-reverse.com Dallas Texas AS36351 SoftLayer Technologies Inc. 75201 United States False tier_2 62 nan
12 192.99.158.241 ip241.ip-192-99-158.net Montréal Quebec AS16276 OVH SAS H3H Canada False tier_2 32 nan
13 35.186.231.97 97.231.186.35.bc.googleusercontent.com Kansas City Missouri AS15169 Google LLC 64106 United States False tier_2 27 True
14 107.162.136.11 nan Seattle Washington AS55002 Defense.Net, Inc 98104 United States False tier_2 27 True
15 3.125.239.17 ec2-3-125-239-17.eu-central-1.compute.amazonaws.com Frankfurt am Main Hesse AS16509 Amazon.com, Inc. 60326 Germany True tier_2 15 nan
16 52.209.203.76 ec2-52-209-203-76.eu-west-1.compute.amazonaws.com Dublin Leinster AS16509 Amazon.com, Inc. D02 Ireland True tier_2 15 nan
17 188.114.97.3 nan San Francisco California AS13335 Cloudflare, Inc. 94107 United States False tier_2 13 True
18 3.126.48.135 ec2-3-126-48-135.eu-central-1.compute.amazonaws.com Frankfurt am Main Hesse AS16509 Amazon.com, Inc. 60326 Germany True tier_2 12 nan
19 52.31.91.108 ec2-52-31-91-108.eu-west-1.compute.amazonaws.com Dublin Leinster AS16509 Amazon.com, Inc. D02 Ireland True tier_2 12 nan
20 208.91.196.46 nan Austin Texas AS40034 Confluence Networks Inc 78701 United States False tier_3 66 nan
21 178.162.228.7 hosted-by.leaseweb.com Frankfurt am Main Hesse AS28753 Leaseweb Deutschland GmbH 60306 Germany True tier_3 29 nan
22 50.97.244.203 clkmg.com San Jose California AS36351 SoftLayer Technologies Inc. 95103 United States False tier_3 4 nan
23 104.26.6.37 nan San Francisco California AS13335 Cloudflare, Inc. 94107 United States False tier_3 3 True
24 50.97.212.250 fa.d4.6132.ip4.static.sl-reverse.com San Jose California AS36351 SoftLayer Technologies Inc. 95103 United States False tier_3 2 nan
25 104.26.7.37 nan San Francisco California AS13335 Cloudflare, Inc. 94107 United States False tier_3 2 True
26 122.10.27.204 nan Hong Kong Central and Western AS62325 HUNGTAK International Network Limited nan Hong Kong False tier_3 2 nan
27 172.67.70.191 nan San Francisco California AS13335 Cloudflare, Inc. 94107 United States False tier_3 2 True
28 69.192.160.55 a69-192-160-55.deploy.static.akamaitechnologies.com Frankfurt am Main Hesse AS16625 Akamai Technologies, Inc. 60326 Germany True tier_3 1 nan
29 23.227.38.65 myshopify.com Ottawa Ontario AS13335 Cloudflare, Inc. K2P Canada False tier_3 1 True

Aggregated redirection graph of domains located on current IP address.¶

  • The redirection flows from left to right
  • Leftmost domains are initial domains hosted on current IP
  • Rightmost domains are final landing domains we were able to crawl

Screenshot of high-occurrence final landing domains¶

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact¶

Zhouhan Chen, zc1245@nyu.edu, Personal Website