INNER CODE UNIT · Python

get_pcap_domains

A3sal0n/CyberThreatHunting · tools/dga-hunt.py:147

def get_pcap_domains(pcap_file, tlds):
    p = re.compile(r'^([a-z0-9]+(-[a-z0-9]+)*\.)+[a-z]{2,}$')
    domains = []
    try:
        packets = rdpcap(pcap_file)
    except IOError:
        print('Pcap file is not present or cannot be opened!')
        print('dga-hunt.py -s <csv/pcap> -i <input file> -o <output file>')
        sys.exit(2)
    for pkt in packets:
        if pkt.haslayer(DNSQR):
            query = pkt[DNSQR].qname.rstrip('.')
            query = query.lower()
            res = p.match(query)
            if res is not None:
                fields = query.split('.')
                if fields[-1] in tlds:
                    domains.append(fields[-2]+'.'+fields[-1])

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…