Fri Jan 13 22:08:15 CET 2017 Automatic Analysis of the domains in this capture. Results maybe be wrong. Using https://github.com/staaldraad/fastfluxanalysis FastFlux Analysis Version: 1.0 (2013) ################################ count ################################ dns.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | dns.msftncsi.com. | 14| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified ([92mClean[0m) Modified Jaroslaw/Patrycja: Score (7) Classified ([92mClean[0m) Rule Based: [92mClean[0m ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified ([92mClean[0m) UTM: Score (0) Classified ([92mClean[0m) MGRS: Score (0) Classified ([92mClean[0m) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified ([92mClean[0m) UTM: Score (0) Classified ([92mClean[0m) MGRS: Score (0) Classified ([92mClean[0m) Combined: Score(0) ---- URL Analysis ---- [93mDomain: dns.msftncsi.com.[0m Entropy analysis (UNIGRAM): [92mBenign[0m Entropy analysis (BIGRAM): [92mBenign[0m Probability analysis (UNIGRAM): [92mBenign[0m Probability analysis (BIGRAM): [92mBenign[0m Total Variation analysis (UNIGRAM): [91mDGA[0m Total Variation analysis (BIGRAM): [91mDGA[0m Naive-Bayesian analysis (UNIGRAM): [92mBenign[0m Naive-Bayesian analysis (BIGRAM): [92mBenign[0m Bayesian analysis (UNIGRAM): [92mBenign[0m Bayesian analysis (BIGRAM): [91mDGA[0m -- ################################ trans_id ################################ www.harvard.edu Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | www.harvard.edu. | 6069| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified ([92mClean[0m) Modified Jaroslaw/Patrycja: Score (6) Classified ([92mClean[0m) Rule Based: [92mClean[0m ---- Geolocation ---- ---- URL Analysis ---- [93mDomain: www.harvard.edu.[0m Entropy analysis (UNIGRAM): [91mDGA[0m Entropy analysis (BIGRAM): [91mDGA[0m Probability analysis (UNIGRAM): [91mDGA[0m Probability analysis (BIGRAM): [91mDGA[0m Total Variation analysis (UNIGRAM): [91mDGA[0m Total Variation analysis (BIGRAM): [91mDGA[0m Naive-Bayesian analysis (UNIGRAM): [91mDGA[0m Naive-Bayesian analysis (BIGRAM): [92mBenign[0m Bayesian analysis (UNIGRAM): [91mDGA[0m Bayesian analysis (BIGRAM): [92mBenign[0m -- ################################ www.kaust.edu.sa Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | www.kaust.edu.sa. | 3379| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified ([92mClean[0m) Modified Jaroslaw/Patrycja: Score (6) Classified ([92mClean[0m) Rule Based: [92mClean[0m ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified ([92mClean[0m) UTM: Score (0) Classified ([92mClean[0m) MGRS: Score (0) Classified ([92mClean[0m) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified ([92mClean[0m) UTM: Score (0) Classified ([92mClean[0m) MGRS: Score (0) Classified ([92mClean[0m) Combined: Score(0) ---- URL Analysis ---- [93mDomain: www.kaust.edu.sa.[0m Entropy analysis (UNIGRAM): [91mDGA[0m Entropy analysis (BIGRAM): [91mDGA[0m Probability analysis (UNIGRAM): [91mDGA[0m Probability analysis (BIGRAM): [91mDGA[0m Total Variation analysis (UNIGRAM): [91mDGA[0m Total Variation analysis (BIGRAM): [91mDGA[0m Naive-Bayesian analysis (UNIGRAM): [91mDGA[0m Naive-Bayesian analysis (BIGRAM): [92mBenign[0m Bayesian analysis (UNIGRAM): [91mDGA[0m Bayesian analysis (BIGRAM): [92mBenign[0m -- ################################ www.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | www.msftncsi.com. | 241| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified ([92mClean[0m) Modified Jaroslaw/Patrycja: Score (7) Classified ([92mClean[0m) Rule Based: [92mClean[0m ---- Geolocation ---- ---- URL Analysis ---- [93mDomain: www.msftncsi.com.[0m Entropy analysis (UNIGRAM): [91mDGA[0m Entropy analysis (BIGRAM): [91mDGA[0m Probability analysis (UNIGRAM): [91mDGA[0m Probability analysis (BIGRAM): [91mDGA[0m Total Variation analysis (UNIGRAM): [91mDGA[0m Total Variation analysis (BIGRAM): [91mDGA[0m Naive-Bayesian analysis (UNIGRAM): [91mDGA[0m Naive-Bayesian analysis (BIGRAM): [92mBenign[0m Bayesian analysis (UNIGRAM): [91mDGA[0m Bayesian analysis (BIGRAM): [92mBenign[0m -- ################################ www.unfoundation.org Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | www.unfoundation.org. | 299| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified ([92mClean[0m) Modified Jaroslaw/Patrycja: Score (7) Classified ([92mClean[0m) Rule Based: [92mClean[0m ---- Geolocation ---- ---- URL Analysis ---- [93mDomain: www.unfoundation.org.[0m Entropy analysis (UNIGRAM): [91mDGA[0m Entropy analysis (BIGRAM): [91mDGA[0m Probability analysis (UNIGRAM): [91mDGA[0m Probability analysis (BIGRAM): [91mDGA[0m Total Variation analysis (UNIGRAM): [91mDGA[0m Total Variation analysis (BIGRAM): [91mDGA[0m Naive-Bayesian analysis (UNIGRAM): [91mDGA[0m Naive-Bayesian analysis (BIGRAM): [92mBenign[0m Bayesian analysis (UNIGRAM): [91mDGA[0m Bayesian analysis (BIGRAM): [92mBenign[0m --