Mon Jul 17 15:05:33 CEST 2017 Automatic Analysis of the domains in this capture. Results maybe be wrong. Using https://github.com/staaldraad/fastfluxanalysis FastFlux Analysis Version: 1.0 (2013) ################################ - ################################ count ################################ ctldl.windowsupdate.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | ctldl.windowsupdate.com. | 1806| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: ctldl.windowsupdate.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): DGA Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): DGA Bayesian analysis (UNIGRAM): DGA Bayesian analysis (BIGRAM): DGA -- ################################ dns.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | dns.msftncsi.com. | 25| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: dns.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): DGA -- ################################ ipv6.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | ipv6.msftncsi.com. | 2564| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: ipv6.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ isatap ################################ ISATAP ################################ isatap.lan ################################ MACBOOKPRO-581D ################################ MERAGHAV-M-H13P ################################ teredo.ipv6.microsoft.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | teredo.ipv6.microsoft.com.| 2844| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: teredo.ipv6.microsoft.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ trans_id ################################ vboxsrv ################################ VBOXSRV ################################ vboxsrv.lan ################################ watson.microsoft.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | watson.microsoft.com. | 172| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: watson.microsoft.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ wer.microsoft.com ################################ win24 ################################ WIN24 ################################ WORKGROUP ################################ \x01\x02__MSBROWSE__\x02 Mon Jul 17 15:36:46 CEST 2017 Automatic Analysis of the domains in this capture. Results maybe be wrong. Using https://github.com/staaldraad/fastfluxanalysis FastFlux Analysis Version: 1.0 (2013) ################################ count ################################ ctldl.windowsupdate.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | ctldl.windowsupdate.com. | 3230| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: ctldl.windowsupdate.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): DGA Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): DGA Bayesian analysis (UNIGRAM): DGA Bayesian analysis (BIGRAM): DGA -- ################################ dns.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | dns.msftncsi.com. | 15| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: dns.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): DGA -- ################################ ipv6.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | ipv6.msftncsi.com. | 1300| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: ipv6.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ isatap ################################ ISATAP ################################ isatap.lan ################################ MACBOOKPRO-581D ################################ MERAGHAV-M-H13P ################################ teredo.ipv6.microsoft.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | teredo.ipv6.microsoft.com.| 1480| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: teredo.ipv6.microsoft.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ trans_id ################################ vboxsrv ################################ VBOXSRV ################################ vboxsrv.lan ################################ watson.microsoft.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | watson.microsoft.com. | 2208| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: watson.microsoft.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ wer.microsoft.com ################################ win24 ################################ WORKGROUP Mon Jul 17 15:38:39 CEST 2017 Automatic Analysis of the domains in this capture. Results maybe be wrong. Using https://github.com/staaldraad/fastfluxanalysis FastFlux Analysis Version: 1.0 (2013) ################################ count ################################ ctldl.windowsupdate.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | ctldl.windowsupdate.com. | 3117| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: ctldl.windowsupdate.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): DGA Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): DGA Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): DGA Bayesian analysis (UNIGRAM): DGA Bayesian analysis (BIGRAM): DGA -- ################################ dns.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | dns.msftncsi.com. | 43| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-25) Classified (Clean) Modified Jaroslaw/Patrycja: Score (7) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- Moran's Index ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score (0) ---- Geary's Coefficient ---- Timezones: Score (0) Classified (Clean) UTM: Score (0) Classified (Clean) MGRS: Score (0) Classified (Clean) Combined: Score(0) ---- URL Analysis ---- Domain: dns.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): DGA -- ################################ ipv6.msftncsi.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | ipv6.msftncsi.com. | 1187| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: ipv6.msftncsi.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): DGA Total Variation analysis (BIGRAM): DGA Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ isatap ################################ ISATAP ################################ isatap.lan ################################ MACBOOKPRO-581D ################################ MERAGHAV-M-H13P ################################ teredo.ipv6.microsoft.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | teredo.ipv6.microsoft.com.| 1367| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: teredo.ipv6.microsoft.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ trans_id ################################ vboxsrv ################################ VBOXSRV ################################ vboxsrv.lan ################################ watson.microsoft.com Qname |TTL |A Records |Ranges |ASNs |Countries |Nameservers | watson.microsoft.com. | 1545| 1| 1| 1| 1| 0| ---- Fast-Flux Scores ---- Modified Thorsten/Holz: Score (-30) Classified (Clean) Modified Jaroslaw/Patrycja: Score (6) Classified (Clean) Rule Based: Clean ---- Geolocation ---- ---- URL Analysis ---- Domain: watson.microsoft.com. Entropy analysis (UNIGRAM): Benign Entropy analysis (BIGRAM): Benign Probability analysis (UNIGRAM): Benign Probability analysis (BIGRAM): Benign Total Variation analysis (UNIGRAM): Benign Total Variation analysis (BIGRAM): Benign Naive-Bayesian analysis (UNIGRAM): Benign Naive-Bayesian analysis (BIGRAM): Benign Bayesian analysis (UNIGRAM): Benign Bayesian analysis (BIGRAM): Benign -- ################################ wer.microsoft.com ################################ win24 ################################ WORKGROUP