A new seed of Murofet #30

Closed
suqitian opened this Issue Dec 1, 2016 · 1 comment

Comments

Projects
None yet
1 participant
@suqitian
Member

suqitian commented Dec 1, 2016

  • MD5
    6f8ba741c1968083265346bff7e9533b

  • VT analysis

  • Domains captured in my virtual machine, 2016-12-01.
    khuqyehgqtpuzzjd.com
    rfcvjqgzlmmesuq.com
    osrlrwsymmlutoq.biz
    osrlrwsymmlutoq.com
    hqognriumjzuqyi.info
    hqognriumjzuqyi.org
    klowmxgxhmriurli.net
    klowmxgxhmriurli.biz
    rxsptmbnuxzdxby.info
    rxsptmbnuxzdxby.com
    motipehktnnfigl.net
    ...

@suqitian

This comment has been minimized.

Show comment
Hide comment
@suqitian

suqitian Dec 2, 2016

Member
  • Seed
    0xa4d7ee01

  • The number of domains
    1259

In order to cover all possibilities, need to generate 1259 domains per day.
17 * 59 + 0x100 = 1259

  • Test
$ python dga.py -d 2016-12-01 -k 0xa4d7ee01
...
rfcvjqgzlmmesuq.com
osrlrwsymmlutoq.biz
osrlrwsymmlutoq.com
hqognriumjzuqyi.info
hqognriumjzuqyi.org
klowmxgxhmriurli.net
klowmxgxhmriurli.biz
rxsptmbnuxzdxby.info
rxsptmbnuxzdxby.com
motipehktnnfigl.net
motipehktnnfigl.org
pffnfxmvzmzsqums.biz
...

dga.py is here

Member

suqitian commented Dec 2, 2016

  • Seed
    0xa4d7ee01

  • The number of domains
    1259

In order to cover all possibilities, need to generate 1259 domains per day.
17 * 59 + 0x100 = 1259

  • Test
$ python dga.py -d 2016-12-01 -k 0xa4d7ee01
...
rfcvjqgzlmmesuq.com
osrlrwsymmlutoq.biz
osrlrwsymmlutoq.com
hqognriumjzuqyi.info
hqognriumjzuqyi.org
klowmxgxhmriurli.net
klowmxgxhmriurli.biz
rxsptmbnuxzdxby.info
rxsptmbnuxzdxby.com
motipehktnnfigl.net
motipehktnnfigl.org
pffnfxmvzmzsqums.biz
...

dga.py is here

@suqitian suqitian closed this Mar 13, 2017

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment