360netlab / DGA

Suspicious DGA from PDNS and Sandbox.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

The DGA of Bigviktor

suqitian opened this issue · comments

  • MD5
    7b1ab096b63480864df7b0dcfebe2e2e
    dd7c9d99d8f7b9975c29c803abdf1c33

  • Our blog about Bigviktor.

  • dga.py is here, Thanks to my colleague Alex.Turing for reversing engineer binary file.

  • Domains generated on 2020/07/10
    decidefresh-county.in
    payculturaltour.org
    standvisiblereach.rocks
    meanforwardcap.top
    raisefitsize.rocks
    www2.tellapartspring.realty
    expectrawknee.com
    decidesurepizza.rocks
    img.leavetall-sky.nl
    dodifferentuser.fans
    ...