Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

From VT: A new key of Murofet V2? #11

Closed
suqitian opened this issue Sep 8, 2016 · 3 comments
Closed

From VT: A new key of Murofet V2? #11

suqitian opened this issue Sep 8, 2016 · 3 comments

Comments

@suqitian
Copy link
Member

suqitian commented Sep 8, 2016

  • MD5
    6d0f3196e91f8ae640791d5bb0d466b7
  • Some domains generated on Sep 09, 2016
    enlwmlrnnrwghtzo.info
    fjshqslnctjjih.com
    fjshqslnctjjih.net
    fnqpwtpnqjrelr.com
    fnqpwtpnqjrelr.info
    fokilqnsjounrky.net
    fokilqnsjounrky.org
    fwiwunhysiobknow.com
    fwiwunhysiobknow.org
    gbrykvuhjyswps.com
    gbrykvuhjyswps.org
    gdsyglrssgouivot.com
    gdsyglrssgouivot.info
    ggmvhppkztszqus.biz
    ggmvhppkztszqus.info
    gresqpvwthsrcoho.biz
    gresqpvwthsrcoho.com
    gwkokphtoqkpphnt.com
    gwkokphtoqkpphnt.net
    gxnxtrdljnhvpb.com
    gxnxtrdljnhvpb.org
    hlmgmsjpckypfto.net
    hlmgmsjpckypfto.org
    hnrkreqknieipzs.com
    hnrkreqknieipzs.info
    hoqunoctsxlirmt.info
    hoqunoctsxlirmt.org
    hpgyloqmkfgieltk.info
    hpgyloqmkfgieltk.org
    htuntitiwlxjtn.biz
    htuntitiwlxjtn.com
    hvekvijjuprlscl.net
    hvekvijjuprlscl.org
    jolgbxtlovrtmnrq.biz
    jolgbxtlovrtmnrq.info
    jpxhnfzphfqvpooj.com
@suqitian
Copy link
Member Author

Domains which generated on Sep 26, 2016.
fdovspiopzsit.com
fdovspiopzsit.info
fwkqjnztmuqnk.com
fwkqjnztmuqnk.info
gmiuslcetzrtoi.com
gmiuslcetzrtoi.net
mphyzqfqgxftiq.biz
mphyzqfqgxftiq.org
nujwkktgxnhkskfi.biz
nujwkktgxnhkskfi.net
qxvksgicitkrnpp.biz
qxvksgicitkrnpp.com
uvslklkqqzuoppre.com
uvslklkqqzuoppre.org

@suqitian
Copy link
Member Author

Seed:
0x8811eea2

Test:

$ python dga.py -d 2016-09-26 -k 0x8811eea2
mduqmsnykuhinnnw.biz
mduqmsnykuhinnnw.com
qmvyspsgtrxypqon.net
...
fdovspiopzsit.info
fdovspiopzsit.com
uvslklkqqzuoppre.org
...
fwkqjnztmuqnk.info
fwkqjnztmuqnk.com
nujwkktgxnhkskfi.net
...

dga.py is here

@suqitian
Copy link
Member Author

In fact, the malware sample only generated 800 domains per day.
But for covering all possibilities, 1020 domains per day was needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant