INNER CODE UNIT · Python
get_pcap_domains
A3sal0n/CyberThreatHunting · tools/dga-hunt.py:147
def get_pcap_domains(pcap_file, tlds):
p = re.compile(r'^([a-z0-9]+(-[a-z0-9]+)*\.)+[a-z]{2,}$')
domains = []
try:
packets = rdpcap(pcap_file)
except IOError:
print('Pcap file is not present or cannot be opened!')
print('dga-hunt.py -s <csv/pcap> -i <input file> -o <output file>')
sys.exit(2)
for pkt in packets:
if pkt.haslayer(DNSQR):
query = pkt[DNSQR].qname.rstrip('.')
query = query.lower()
res = p.match(query)
if res is not None:
fields = query.split('.')
if fields[-1] in tlds:
domains.append(fields[-2]+'.'+fields[-1])