360netlab/DGA

From VT: A length of 12-16, a-z. tlds: [biz, com, info, net, org]

suqitian opened this issue · 0 comments

  • MD5
    9690bee17e9d4b83ae584f5d91849a6e
  • DNS requests in [VT]
    iieqqoytgohjytil.com
    iieqqoytgohjytil.info
    kpjprkqhsmqrmsj.org
    njpqlupthfhwxqns.com
    njpqlupthfhwxqns.org
    qwdlnpptqrgsdprf.net
    qwdlnpptqrgsdprf.org
    wtgtpbrzogowkjt.biz
    wtgtpbrzogowkjt.com
  • Then run it again in our Cuckoo Sandbox, DNS requests was a noticeable difference from the VT one.
    nmqgnfwphujk.biz
    nmqgnfwphujk.com
    znhignykyyfrdlj.info
    znhignykyyfrdlj.com
    thrusjzvpgjpaikl.net
    thrusjzvpgjpaikl.biz
    cvyqpjqvjdplssq.info
    cvyqpjqvjdplssq.com
    rvqoovmmoqptspi.org
    rvqoovmmoqptspi.com
    oqrivpkkeujnqrrq.biz
    oqrivpkkeujnqrrq.org
    lsurhmvpmzkhwp.net
    lsurhmvpmzkhwp.com
    qkqxtfwunoyogxkp.info
    qkqxtfwunoyogxkp.biz
    pjrvnrqspptzn.net
    pjrvnrqspptzn.org
    qrstrupvskriebvw.info
    qrstrupvskriebvw.com
    mkqpykkpqyuul.biz
    mkqpykkpqyuul.com
    gyrhkosqoisgkfn.info
    gyrhkosqoisgkfn.org
    txhohmpovjstukpi.net
    txhohmpovjstukpi.biz
  • Should it be a time dependent DGA?