diff options
Diffstat (limited to 'test/results/flow-info/default/bad-dns-traffic.pcap.out')
-rw-r--r-- | test/results/flow-info/default/bad-dns-traffic.pcap.out | 34 |
1 files changed, 17 insertions, 17 deletions
diff --git a/test/results/flow-info/default/bad-dns-traffic.pcap.out b/test/results/flow-info/default/bad-dns-traffic.pcap.out index 03459e53e..a33483876 100644 --- a/test/results/flow-info/default/bad-dns-traffic.pcap.out +++ b/test/results/flow-info/default/bad-dns-traffic.pcap.out @@ -3,24 +3,24 @@ DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] new: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] detected: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][05e100a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][958700a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][958700a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name new: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] detected: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][244300fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][6b5000fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][e18f00fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][46b100fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][c75900fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][c75900fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name analyse: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.063| 4.102| 1.074| 0.689| 474850.951| 4.700] @@ -32,20 +32,20 @@ [PKTLENS.....: 119,119,119,119,119,150,81,116,81,81,112,81,114,81,116,81,114,81,114,81,112,81,114,81,116,81,114,81,81,160,276,309] [ENTROPIES...: 4.9,5.0,5.0,5.0,5.0,4.9,5.0,5.0,5.0,5.1,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,4.9,5.0,4.9,5.0,5.0,5.0,5.0,5.0,4.9,4.2,4.3] update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name new: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] detected: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][a05700e6da83510001636f6e736f6c65202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Unidirectional Traffic + RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][a05700e6da83510001636f6e736f6c65202873697276696d65732900.skullseclabs.org] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name idle: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name idle: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name idle: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] - RISK: Susp DGA Domain name, Risky Domain Name + RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name DAEMON-EVENT: shutdown |