360netlab / DGA

Suspicious DGA from PDNS and Sandbox.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

From sandbox: A fix length of 10, hexadecimal notation, tlds:[pw]

suqitian opened this issue · comments

0137c9948c.pw
10187cdf58.pw
469255523b.pw
59e68dd72f.pw
5ce5a3010e.pw
8aa2f2db8e.pw
b0e94453c7.pw
c7d7c9b876.pw
c983ad2490.pw
d02f264235.pw
d0cb5d08cd.pw
e64b1e1e2d.pw
fe5a7035db.pw
...
  • Another cluster on 2018-06-07
cc9089dfb9.pw
8a66446ab5.pw
5149aecef4.pw
c7ea5c7056.pw
...
  • The sample was packed by VMP and hard to crack