Fri Jan 13 14:19:57 CET 2017 Automatic Analysis of the domains in this capture. Results maybe be wrong. Using https://github.com/staaldraad/fastfluxanalysis FastFlux Analysis Version: 1.0 (2013) ################################ BING.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | BING.COM. | 1785| 2| 2| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-28) Classified (Clean) Modified Jaroslaw/Patrycja: Score (8) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: BING.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ BOIBLEVED.RU ################################ count ################################ dns.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | dns.msftncsi.com. | 9| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: dns.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): DGA -- ################################ google.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | google.com. | 299| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: google.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ GOOGLE.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | GOOGLE.COM. | 299| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: GOOGLE.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ http ################################ HTTP ################################ IATITAINU.RU ################################ LIGEDACKO.RU ################################ MICROSOFT.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | MICROSOFT.COM. | 822| 5| 5| 1| 3| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-24) Classified (Clean) Modified Jaroslaw/Patrycja: Score (20) Classified (Fast-Flux) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (-0.148933375635) Classified (Fast-Flux) UTM: Score (-0.215364975613) Classified (Fast-Flux) MGRS: Score (-0.269704356054) Classified (Fast-Flux) Combined: Score (-0.0086507760699) ---- Geary's Coefficient ---- Timezones: Score (0.945224710632) Classified (Fast-Flux) UTM: Score (0.914857000559) Classified (Fast-Flux) MGRS: Score (1.06784967188) Classified (Fast-Flux) Combined: Score(0.923418138233) ---- URL Analysis ---- Domain: MICROSOFT.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ ORREREIDE.RU ################################ OSSTISPER.RU ################################ SCOMUMPEE.RU ################################ SECERRIMS.RU ################################ SIMPLYBOT.CO ################################ tclogz.tk ################################ trans_id ################################ TURERKILA.RU ################################ VACCAPLOG.RU ################################ WIN1 ################################ www.google.cz Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | www.google.cz. | 299| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: www.google.cz. Entropy analysis (UNIGRAM): DGA Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): DGA Probability analysis (BIGRAM): DGA Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): DGA Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): DGA Bayesian analysis (BIGRAM): Benign -- ################################ YAHOO.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | YAHOO.COM. | 577| 3| 3| 3| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (9) Classified (Fast-Flux) Modified Jaroslaw/Patrycja: Score (14) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: YAHOO.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ yandex.ru Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | yandex.ru. | 64| 4| 2| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-21) Classified (Clean) Modified Jaroslaw/Patrycja: Score (11) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: yandex.ru. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): DGA Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): DGA Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): DGA Bayesian analysis (BIGRAM): Benign -- ################################ YANDEX.RU Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | YANDEX.RU. | 70| 4| 2| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-21) Classified (Clean) Modified Jaroslaw/Patrycja: Score (11) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: YANDEX.RU. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): DGA Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): DGA Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): DGA Bayesian analysis (BIGRAM): Benign -- ################################ 1.K5SERVICE.ORG Empty Response section ################################ 1.WINSRW.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | 1.WINSRW.COM. | 7020| 5| 2| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-24) Classified (Clean) Modified Jaroslaw/Patrycja: Score (11) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: 1.WINSRW.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ 2.K5SERVICE.ORG Empty Response section ################################ 2.WINSRW.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | 2.WINSRW.COM. | 6781| 7| 3| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-22) Classified (Clean) Modified Jaroslaw/Patrycja: Score (15) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: 2.WINSRW.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ 3.K5SERVICE.ORG Empty Response section ################################ 3.WINSRW.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | 3.WINSRW.COM. | 2547| 3| 3| 2| 2| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-8) Classified (Clean) Modified Jaroslaw/Patrycja: Score (14) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (-1.0) Classified (Fast-Flux) MGRS: Score (-1.0) Classified (Fast-Flux) Combined: Score (0.0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (1.5) Classified (Fast-Flux) MGRS: Score (1.5) Classified (Fast-Flux) Combined: Score(0.0) ---- URL Analysis ---- Domain: 3.WINSRW.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ 4.K5SERVICE.ORG Empty Response section ################################ 4.WINSRW.COM Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | 4.WINSRW.COM. | 7199| 10| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-18) Classified (Clean) Modified Jaroslaw/Patrycja: Score (15) Classified (Clean) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: 4.WINSRW.COM. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ 5.K5SERVICE.ORG Empty Response section ################################ 5.WINSRW.COM ################################ 67G57J44K7H.WS Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | 67G57J44K7H.WS. | 1531| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: 67G57J44K7H.WS. Entropy analysis (UNIGRAM): DGA Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign --