360netlab / DGA

Suspicious DGA from PDNS and Sandbox.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

The DGA of Vidro

suqitian opened this issue · comments

  • MD5
    c41a86e735944a6ec0b2268e89d02ae3

  • VT analysis

  • Domains generated on 2016/10/09
    rcmauito.dyndns.org
    oxhfifdtsp.net
    vcblwmoxnl.com
    jxsuqajadqe.com
    dxvrkjy.dyndns.org
    ccyoctjwj.net
    ndkcaponuvsf.com
    bybkudu.com
    idvqyku.dyndns.org
    tehoggkwbd.net
    qypwmhejay.net
    uyeiowzs.dyndns.org
    aeoqmnvfx.dyndns.org
    cztkypubdzyf.com
    wzmisyzs.dyndns.org
    gflsieq.com
    pescerpomekh.com
    wcvbgvws.com
    hziwqufksie.net
    igttmgqfc.com
    vfzekikxjm.net
    hcgpeqbkojn.dyndns.org
    ngivollorwkk.net
    scsdcmrbzkrk.net
    oafywbatoa.dyndns.org
    vhxxyehxfobd.dyndns.org
    jarnuwgaarw.net
    ohavsxm.net
    uacbcsvs.com
    zhmjqtrg.com
    bfwhqzfw.dyndns.org
    ydpgidcawtf.dyndns.org
    pbozanbjw.dyndns.org
    gijlwam.net
    tgfhucgxxo.dyndns.org
    femsokxjs.com
    abznyjqbrbpy.net
    migycrhonxt.dyndns.org
    nddrkhwtl.com
    hjsmacnfi.net
    bivkuvcwbg.com
    letuubs.net
    udaegoss.net
    zkkcepyg.net
    aexgmfnboche.dyndns.org
    okzogti.dyndns.org
    tjnayydxtq.com
    sfqwqincvmaq.dyndns.org
    gfeismykkug.com
    ukwackdxbzk.com
    nfbuydtth.net
    mlergneojjm.com
    bltdirywyh.net
    egklcguky.net
    flhokwj.dyndns.org
    smltmezxp.net
    tgzxuuo.dyndns.org
    gidlgsukgw.net
    ahgzabjbknqt.com
    qorvwxvxut.dyndns.org
    xmafoijf.dyndns.org
    nianczqtd.dyndns.org
    ygniwzzbse.com
    yjlbkvvbofhm.net
    riozeok.com
    monkujaopkv.net
    emxhkpf.com
    xoyycegg.com
    knutqgayxac.net
    lhrnyxptv.dyndns.org
    znifslug.dyndns.org
    fnghocfpisxu.com
    ejsegmqkvy.dyndns.org
    tjxqiql.com

  • TLDs
    ['dyndns.org', 'com', 'net']

  • The number of domains
    100 per week

  • Test

$ python dga.py -n 100 -t `date +%s -d "2016-10-09"`
dxvrkjy.dyndns.org
vcblwmoxnl.com
oxhfifdtsp.net
rcmauito.dyndns.org
jxsuqajadqe.com
ccyoctjwj.net
uyeiowzs.dyndns.org
ndkcaponuvsf.com
qypwmhejay.net
idvqyku.dyndns.org
bybkudu.com
tehoggkwbd.net
wzmisyzs.dyndns.org
pescerpomekh.com
hziwqufksie.net
aeoqmnvfx.dyndns.org
cztkypubdzyf.com
vfzekikxjm.net
oafywbatoa.dyndns.org
gflsieq.com
jarnuwgaarw.net
bfwhqzfw.dyndns.org
uacbcsvs.com
ngivollorwkk.net
......

The output are well-matched to the domains generated by sample.
dga.py is here.