360netlab/DGA

From PDNS: New seed of proslikefan DGA?

suqitian opened this issue · 1 comments

  • These past two weeks, DNS requests of these domains have been active, the number of clients reached hundreds.
    awaptfhcywz.biz
    bomffwnm.biz
    dkrwpi.net
    ecxpij.net
    eubuesq.biz
    fxbxpeo.ru
    gputzirpn.ru
    hafuvgg.biz
    hhheoujfk.ru
    iiixhbxj.biz
    ioxmpbwzd.info
    ipsxnpr.ru
    izolchilyv.ru
    jhcwhynhh.ru
    jhzxgxgji.eu
    jroptwvq.ru
    jyiruhuve.info
    kjzghtkx.ru
    koajzeef.eu
    kzoxbfqm.eu
    lbfcnjyf.ru
    lrogqk.eu
    lwtpvavi.info
    mcigspygl.info
    mjyjpzw.eu
    mywwwpdjq.eu
    myyajf.ru
    nqxcfnnbjs.eu
    nsnmcewnhs.info
    omvqqsz.se
    pcialmfe.com
    peqehgtd.se
    pmkodzc.in
    prmgxr.name
    qewrpffwv.org
    qhocqqov.name
    qkfrlza.com
    qssrzy.in
    ralqflyjvv.in
    rdswccti.se
    rmqquixisq.org
    rpulgh.name
    rwmneqv.com
    sfgwcdn.com
    sievgcoalr.in
    sokxihuec.com
    spiygv.org
    syjdikt.name
    tqxsbtk.name
    tvyklbcuja.in
    txaveyno.org
    txkoyliwf.com
    udchrwc.in
    ufphng.org
    upkkzmu.com
    usbvhxga.name
    uyggbvqore.in
    vhayrog.com
    vnakhug.org
    vwzzosjdz.net
    xgzedqycbs.net
  • Regex results from DGArchive show that it is a DGA of proslikefan

It should not be the DGA of Proslikefan, because the same domains were used every day.
And Proslikefan is a time dependent DGA.