Sat Jun 24 22:46:19 CEST 2017 Automatic Analysis of the domains in this capture. Results maybe be wrong. Using https://github.com/staaldraad/fastfluxanalysis FastFlux Analysis Version: 1.0 (2013) ################################ count ################################ dist.torproject.org Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | dist.torproject.org. | 296| 6| 6| 5| 3| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (55) Classified (Fast-Flux) Modified Jaroslaw/Patrycja: Score (29) Classified (Fast-Flux) Rule Based: Fast-Flux ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (-0.128662551654) Classified (Fast-Flux) UTM: Score (-0.225510403596) Classified (Fast-Flux) MGRS: Score (-0.170579587313) Classified (Fast-Flux) Combined: Score (-0.00494932304919) ---- Geary's Coefficient ---- Timezones: Score (0.785921017859) Classified (Fast-Flux) UTM: Score (0.905635423009) Classified (Fast-Flux) MGRS: Score (1.0077748464) Classified (Fast-Flux) Combined: Score(0.717291721909) ---- URL Analysis ---- Domain: dist.torproject.org. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ dns.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | dns.msftncsi.com. | 18| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: dns.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): DGA -- ################################ trans_id ################################ www.dropbox.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | www.dropbox.com. | 32| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: www.dropbox.com. Entropy analysis (UNIGRAM): DGA Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): DGA Probability analysis (BIGRAM): DGA Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): DGA Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): DGA Bayesian analysis (BIGRAM): Benign --