Homas / ioc2rpz

ioc2rpz is a place where threat intelligence meets DNS.
Apache License 2.0
105 stars 17 forks source link

check mixed zones updates #19

Closed Homas closed 2 years ago

Homas commented 4 years ago

Check mixed zones updates. Probably an issue with incremental updates. incsupdate.tumblr.com.phishtank.ioc2rpz. 900 IN CNAME . *.incsupdate.tumblr.com.phishtank.ioc2rpz. 900 IN CNAME . quickfollowers.net.phishtank.ioc2rpz. 900 IN CNAME . *.quickfollowers.net.phishtank.ioc2rpz. 900 IN CNAME . 32.78.44.180.107.rpz-ip.phishtank.ioc2rpz. 230400 CLASS256 TYPE1280 \# 256 0A61756E74652D6D616461C0F50005000100000384000100012AC1FB 00050001000003840001001870707265766965772D7765627363726D 376F61366535397006636E616F7661C0710005000100000384000100 012AC222000500010000038400010014636F6E6669726D2D796F7572 2D6163636F756E7411726F736564616C657061726B6E6F727468C071 0005000100000384000100012AC25E00050001000003840001000670 617970616C0F616964616E31323334353637383938047265706C0263 6FC0330005000100000384000100012AC2A100050001000003840001 000E64737266647A696E736D6B6465770B63726561746F726C696E6B C0A10005 . 2214592768 CH URI 49884 5 "\000\001\000\000\003\132\000\001\000\020outlookadministartor\194\235\000\005\000\001\000\000\003\132\000\001\000\001*\195\019\000\005\000\001\000\000\003\132\000\001\000\010god-marine\192\245\000\005\000\001\000\000\003\132\000\001\000\001*\195D\000\005\000\001\000\000\003\132\000\001\000\028f68616e67696e67666c6f27login\192\245\000\005\000\001\000\000\003\132\000\001\000\001*\195k\000\005\000\001\000\000\003\132\000\001\000\010gon-macona\192\245\000\005\000\001\000\000\003\132\000\001\000\001*\195\164\000\005\000\001\000\000\003\132\000\001\000\012webex-secure\192q\000\005\000\001\000\000\003\132\000\001\000\001*\195\203\000\005\000\001\000\000\003\132\000\001\000\014briandesmarais\192q\000\005\000\001\000\000\003\132\000\001\000\001*\195\244\000\005\000\001\000\000\003\132\000\001\000\009morfil-fm\006blogcu" com.phishtank.ioc2rpz. 900 IN CNAME . *.morfil-fm.blogcu.com.phishtank.ioc2rpz. 900 IN CNAME . secure.runescape.com-xl.ru.phishtank.ioc2rpz. 900 IN CNAME . *.secure.runescape.com-xl.ru.phishtank.ioc2rpz. 900 IN CNAME .

begin-effard.firebaseapp.com.phishtank.ioc2rpz. 900 IN CNAME . *.begin-effard.firebaseapp.com.phishtank.ioc2rpz. 900 IN CNAME . tyrannisesprices.net.phishtank.ioc2rpz. 900 IN CNAME . *.tyrannisesprices.net.phishtank.ioc2rpz. 900 IN CNAME . www.postfinance-checkout.ch.phishtank.ioc2rpz. 900 IN CNAME . *.www.postfinance-checkout.ch.phishtank.ioc2rpz. 900 IN CNAME . 32.189.177.206.116.rpz-ip.phishtank.ioc2rpz. 230400 CLASS256 TYPE1280 \# 256 037777771064616373616E6461696C6F6370686174C03A0005000100 000384000100012AD8B200050001000003840001000767696E2D756E 61C1590005000100000384000100012AD8E300050001000003840001 0002333201340239380331323603313135D88E000500010000038400 010005626C6F627302636F02696CC03E000500010000038400010001 2AD924000500010000038400010011616C6973616E74796C6F617235 736664640674756D626C72C0F00005000100000384000100012AD94C 00050001000003840001000233320331333303313330033130330331 3736D88E00050001000003840001000A6F6D652D646F6E657261C159 00050001 ;; Got bad packet: bad label type 16532 bytes 9c 8e 80 a0 00 01 02 b9 00 00 00 01 09 70 68 69 .............phi 73 68 74 61 6e 6b 07 69 6f 63 32 72 70 7a 00 00 shtank.ioc2rpz.. fc 00 01 13 76 65 72 69 66 69 6b 61 73 69 2d 61 ....verifikasi-a 63 63 6f 75 6e 74 74 07 77 65 62 6e 6f 64 65 03 ccountt.webnode. 63 6f 6d 09 70 68 69 73 68 74 61 6e 6b 07 69 6f com.phishtank.io 63 32 72 70 7a 00 00 05 00 01 00 00 03 84 00 01 c2rpz...........

Homas commented 4 years ago

Probably fixed in the dev branch. Not sure why it didn't work only in certain cases.