360netlab / DGA

Suspicious DGA from PDNS and Sandbox.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

From 360TI: A new version of Shiotob

suqitian opened this issue · comments

  • MD5
    ddc16b26c2cd6f8d157bed810bf944f4
  • The new seed of Shiotob was found by 360TI.
    The DGA's python code was based on the version that implemented by baderj.
  • Test
$ python dga.py -d panisdar.com -v 2
panisdar.com
vmvhsmno.net
cggjy4f5.com
cyjwf5wxgz5.net
f31tmaj4izf.com
3ct3rfebxxf.net
xqw51hvyqyj.com
w1saogg3o9ont.net
c3sddlmrc3ojm.com
jf91bxpfyda2r.net
u4tvtku5922gh.com
49kyqanhjpfrnt1.net
ezvkzbpvuna9lrd.com
tg3ent5kawyrmsq.net
pw5wrwr5rh5cwwb.com
uvh1jnqgratmpk9.net
osidy5uynkht2jn.com
en5tyqin21qdw.net
zycwu4cwln2s4.com
bnwnt4ecm9ge.net
5jisydwclnwd.com
zvyu9f2w5z1e.net
zkjrwiwakm.com
qgdj9nlwgi4s.net
yxgdx4xytzx1.com
wfm1h3eo95gc.net
gimil51cgq3o.com
44iexxyb9j3b.net
3lu4kf3gnz1.com
isyc3gd2d3m9h.net
onxzojgpdyl4l.com
z51dr1uytwbpf.net
ct3qcnqxq4bxt.com
49scaf1niqt3e.net
9whsc1j3wso.com
mxpe5wzd4v.net
4ft31kqh2t.com
g9kewua2wd.net
...

dga.py is here.