summaryrefslogtreecommitdiff
path: root/test/results/flow-info/default/bad-dns-traffic.pcap.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/flow-info/default/bad-dns-traffic.pcap.out')
-rw-r--r--test/results/flow-info/default/bad-dns-traffic.pcap.out34
1 files changed, 17 insertions, 17 deletions
diff --git a/test/results/flow-info/default/bad-dns-traffic.pcap.out b/test/results/flow-info/default/bad-dns-traffic.pcap.out
index 03459e53e..a33483876 100644
--- a/test/results/flow-info/default/bad-dns-traffic.pcap.out
+++ b/test/results/flow-info/default/bad-dns-traffic.pcap.out
@@ -3,24 +3,24 @@
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53]
detected: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][05e100a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][958700a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][958700a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
new: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53]
detected: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][244300fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][6b5000fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][e18f00fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][46b100fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][c75900fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][c75900fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
analyse: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: 0.063| 4.102| 1.074| 0.689| 474850.951| 4.700]
@@ -32,20 +32,20 @@
[PKTLENS.....: 119,119,119,119,119,150,81,116,81,81,112,81,114,81,116,81,114,81,114,81,112,81,114,81,116,81,114,81,81,160,276,309]
[ENTROPIES...: 4.9,5.0,5.0,5.0,5.0,4.9,5.0,5.0,5.0,5.1,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,4.9,5.0,4.9,5.0,5.0,5.0,5.0,5.0,4.9,4.2,4.3]
update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
new: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53]
detected: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][a05700e6da83510001636f6e736f6c65202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Unidirectional Traffic
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic
detection-update: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][a05700e6da83510001636f6e736f6c65202873697276696d65732900.skullseclabs.org]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
idle: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
idle: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
idle: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable]
- RISK: Susp DGA Domain name, Risky Domain Name
+ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name
DAEMON-EVENT: shutdown