swedish dns zone enumerator
i have blocked a zone enumerator, though i guess they will be a whack-a-mole others have reported them as well /home/randy> sudo tcpdump -pni vtnet0 -c 10 port 53 and net 193.235.141 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on vtnet0, link-type EN10MB (Ethernet), capture size 262144 bytes 22:42:39.516849 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? 33j4h.org.al. (30) 22:42:39.517640 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? 33m6d.xn--mgbayh7gpa. (38) 22:42:39.519169 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? 33lxd.tn. (26) 22:42:39.520064 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? 33md6.jo. (26) 22:42:39.521081 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? 33lxd.lb. (26) 22:42:39.523981 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? 33pd2.az. (26) 22:42:39.525043 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? 33nc5.com.al. (30) 22:42:39.526185 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? 33nc5.sz. (26) 22:42:39.527931 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? 33q5p.com.al. (30) 22:42:39.529516 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? 33qbq.com.al. (30) 10 packets captured 124 packets received by filter 0 packets dropped by kernel inetnum: 193.235.141.0 - 193.235.141.255 netname: domaincrawler-hosting descr: domaincrawler hosting org: ORG-ABUS1196-RIPE country: SE admin-c: VIJE1-RIPE tech-c: VIJE1-RIPE status: ASSIGNED PA notify: c+1196@resilans.se mnt-by: RESILANS-MNT mnt-routes: ETTNET-LIR created: 2008-04-03T11:21:00Z last-modified: 2017-04-10T12:47:06Z source: RIPE randy
Randy, thanks for sharing, I didn't know this is actually done. Any idea if they use something clever or just exhaustive search? thanks Amir -- Amir Herzberg Comcast professor of Security Innovations, Computer Science and Engineering, University of Connecticut Homepage: https://sites.google.com/site/amirherzberg/home `Applied Introduction to Cryptography' textbook and lectures: https://sites.google.com/site/amirherzberg/cybersecurity On Tue, Oct 31, 2023 at 6:49 PM Randy Bush <randy@psg.com> wrote:
i have blocked a zone enumerator, though i guess they will be a whack-a-mole
others have reported them as well
/home/randy> sudo tcpdump -pni vtnet0 -c 10 port 53 and net 193.235.141 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on vtnet0, link-type EN10MB (Ethernet), capture size 262144 bytes 22:42:39.516849 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? 33j4h.org.al. (30) 22:42:39.517640 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? 33m6d.xn--mgbayh7gpa. (38) 22:42:39.519169 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? 33lxd.tn. (26) 22:42:39.520064 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? 33md6.jo. (26) 22:42:39.521081 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? 33lxd.lb. (26) 22:42:39.523981 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? 33pd2.az. (26) 22:42:39.525043 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? 33nc5.com.al. (30) 22:42:39.526185 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? 33nc5.sz. (26) 22:42:39.527931 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? 33q5p.com.al. (30) 22:42:39.529516 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? 33qbq.com.al. (30) 10 packets captured 124 packets received by filter 0 packets dropped by kernel
inetnum: 193.235.141.0 - 193.235.141.255 netname: domaincrawler-hosting descr: domaincrawler hosting org: ORG-ABUS1196-RIPE country: SE admin-c: VIJE1-RIPE tech-c: VIJE1-RIPE status: ASSIGNED PA notify: c+1196@resilans.se mnt-by: RESILANS-MNT mnt-routes: ETTNET-LIR created: 2008-04-03T11:21:00Z last-modified: 2017-04-10T12:47:06Z source: RIPE
randy
While I see evidence for the claim, 5 character left hand label and all non-existant. I also see QNAME minimisation in action as the QTYPE is NS. This could just be a open recursive servers using QNAME minimisation. With QNAME minimisation working correctly all parent zones should see is NS queries with the occasional DNSKEY and DS query. Both BIND and Knot use NS queries for QNAME minimisation. Other query types and/or prefixes do not work as they have undesirable side effects. I would not like anyone to take seeing mostly NS queries as any evidence of bad practice. On the contrary, this is best practice. It’s just relatively new. I would also like to remind everyone here that QNAME minimisation using NS queries will expose the bad practice of having mis-matching NS RRsets above and below the zone cut and having garbage NS RRsets in the child zone when both parent and child are served by the same servers. Please ensure your NS RRsets are consistent on both sides of the zone cut and that they are sane. Mark
On 1 Nov 2023, at 09:46, Randy Bush <randy@psg.com> wrote:
i have blocked a zone enumerator, though i guess they will be a whack-a-mole
others have reported them as well
/home/randy> sudo tcpdump -pni vtnet0 -c 10 port 53 and net 193.235.141 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on vtnet0, link-type EN10MB (Ethernet), capture size 262144 bytes 22:42:39.516849 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? 33j4h.org.al. (30) 22:42:39.517640 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? 33m6d.xn--mgbayh7gpa. (38) 22:42:39.519169 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? 33lxd.tn. (26) 22:42:39.520064 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? 33md6.jo. (26) 22:42:39.521081 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? 33lxd.lb. (26) 22:42:39.523981 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? 33pd2.az. (26) 22:42:39.525043 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? 33nc5.com.al. (30) 22:42:39.526185 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? 33nc5.sz. (26) 22:42:39.527931 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? 33q5p.com.al. (30) 22:42:39.529516 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? 33qbq.com.al. (30) 10 packets captured 124 packets received by filter 0 packets dropped by kernel
inetnum: 193.235.141.0 - 193.235.141.255 netname: domaincrawler-hosting descr: domaincrawler hosting org: ORG-ABUS1196-RIPE country: SE admin-c: VIJE1-RIPE tech-c: VIJE1-RIPE status: ASSIGNED PA notify: c+1196@resilans.se mnt-by: RESILANS-MNT mnt-routes: ETTNET-LIR created: 2008-04-03T11:21:00Z last-modified: 2017-04-10T12:47:06Z source: RIPE
randy
-- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: marka@isc.org
ya, right, and at a whole bunch of other cctld servers from a network called domaincrawler-hosting shall we smoke another? /home/randy> sudo tcpdump -pni vtnet0 -c 500 port 53 and net 193.235.141 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on vtnet0, link-type EN10MB (Ethernet), capture size 262144 bytes 05:12:30.563268 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? cgatcity.com.cu. (33) 05:12:30.565017 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? christ-jockel.jo. (34) 05:12:30.565660 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? cgatcity.al. (29) 05:12:30.566490 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? cgatcity.org.al. (33) 05:12:30.566694 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? christian-luber-jr.net.al. (43) 05:12:30.569474 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? clearing-muenchen.eg. (38) 05:12:30.571870 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? clearing-muenchen.com.ps. (42) 05:12:30.573436 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? cofls-welt.xn--pgbs0dh. (40) 05:12:30.573914 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? club-lederwerk-neustadt.net.al. (48) 05:12:30.574608 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? cofls-welt.az. (31) 05:12:30.575203 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? cofls-welt.lb. (31) 05:12:30.575356 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? conomix.eg. (28) 05:12:30.575950 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? conomix.net.ps. (32) 05:12:30.577242 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? computercheck-online.tn. (41) 05:12:30.577800 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? conomix.cu. (28) 05:12:30.578272 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? conomix.net.lb. (32) 05:12:30.578480 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? cstreibel.lr. (30) 05:12:30.578896 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? cstreibel.org.lb. (34) 05:12:30.579060 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? cristallcard.az. (33) 05:12:30.580681 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? d-cypher.tn. (29) 05:12:30.581812 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? d-cypher.al. (29) 05:12:30.582157 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? dailycatesse.sz. (33) 05:12:30.582381 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? d-cypher.eg. (29) 05:12:30.583340 IP 193.235.141.125.32768 > 666.42.7.11.53: 14 NS? damensattel-duesseldorf.net.ps. (48) 05:12:30.583439 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? dailycatesse.az. (33) 05:12:30.584078 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? dailycatesse.mw. (33) 05:12:30.584330 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? dailycatesse.org.al. (37) 05:12:30.584730 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? darkroom24.net.al. (35) 05:12:30.585506 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? damensattel-duesseldorf.jo. (44) 05:12:30.585995 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? dassehen.lr. (29) 05:12:30.587759 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? darkroom24.tn. (31) 05:12:30.588076 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? dgurock.org.al. (32) 05:12:30.589055 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? dictys.jo. (27) 05:12:30.589640 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? dgurock.az. (28) 05:12:30.591432 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? dictys.com.ps. (31) 05:12:30.592608 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? disko-thema.org.al. (36) 05:12:30.593365 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? diesling-1.net.al. (35) 05:12:30.593814 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? diesling-1.ps. (31) 05:12:30.595057 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? disko-thema.net.al. (36) 05:12:30.595722 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? disko-thema.xn--mgbayh7gpa. (44) 05:12:30.596496 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? downbeat-band.com.lb. (38) 05:12:30.596898 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? dj-hc-team.sz. (31) 05:12:30.598077 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? dnd-testdomain.net.al. (39) 05:12:30.598203 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? dnd-testdomain.net.ps. (39) 05:12:30.598338 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? druck-hamster.lr. (34) 05:12:30.599224 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? druckerei-hilden.az. (37) 05:12:30.602031 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? druckerei-hilden.com.lb. (41) 05:12:30.604763 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? drumandy.xn--pgbs0dh. (38) 05:12:30.605420 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? dugehoerstmir.tz. (34) 05:12:30.607074 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? dugehoerstmir.eg. (34) 05:12:30.607465 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? dugehoerstmir.net.lb. (38) 05:12:30.608142 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? xn--kostogkrft-k6a.al. (39) 05:12:30.608867 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? xn--rkenvej-p1a.com.al. (40) 05:12:30.610043 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? xn--ombygningsln-3cb.cu. (41) 05:12:30.613031 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? xn--sportholbk-l6a.com.lb. (43) 05:12:30.613510 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? xn--sportholbk-l6a.mw. (39) 05:12:30.613660 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? xn--sportholbk-l6a.net.ps. (43) 05:12:30.613911 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? yumlife.lr. (28) 05:12:30.614575 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? yumlife.tn. (28) 05:12:30.615677 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? yumlife.al. (28) 05:12:30.616176 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? yumlife.cu. (28) 05:12:30.617347 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? zensolutions.az. (33) 05:12:30.619396 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? zonebente.jo. (30) 05:12:30.620738 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? acas.com.lb. (29) 05:12:30.620884 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? acomacoestepr.al. (34) 05:12:30.621900 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? acere.az. (26) 05:12:30.622118 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? acomacoestepr.sz. (34) 05:12:30.622755 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? acere.net.ps. (30) 05:12:30.623809 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? alfamob.al. (28) 05:12:30.624673 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? acomacoestepr.xn--mgbayh7gpa. (46) 05:12:30.624943 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? aeerj.az. (26) 05:12:30.624962 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? alfamob.org.lb. (32) 05:12:30.625567 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? aeerj.lr. (26) 05:12:30.626919 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? amao.az. (25) 05:12:30.627264 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? alfamob.net.ps. (32) 05:12:30.628910 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? alemdaideia.net.ps. (36) 05:12:30.629337 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? alemdaideia.tn. (32) 05:12:30.629996 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? aparelhodigestivo.xn--pgbs0dh. (47) 05:12:30.630926 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? artvenite.net.lb. (34) 05:12:30.631583 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? belemportal.al. (32) 05:12:30.631608 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? aparelhodigestivo.eg. (38) 05:12:30.633330 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? artvenite.lr. (30) 05:12:30.635616 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? belemportal.xn--pgbs0dh. (41) 05:12:30.637710 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? cassiturismo.az. (33) 05:12:30.639069 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? cassiturismo.sz. (33) 05:12:30.639311 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? cartolinadesign.lr. (36) 05:12:30.639724 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? cerimonialmariah.eg. (37) 05:12:30.640816 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? cassiturismo.jo. (33) 05:12:30.640892 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? cassiturismo.lr. (33) 05:12:30.641266 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? colegioiguacu.jo. (34) 05:12:30.641496 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? colegioiguacu.net.al. (38) 05:12:30.642908 IP 193.235.141.125.32768 > 666.42.7.11.53: 14 NS? conceitorio.lr. (32) 05:12:30.646825 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? csrb.lb. (25) 05:12:30.647078 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? doceriaexpress.com.ps. (39) 05:12:30.648381 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? fabiangehrke.com.al. (37) 05:12:30.648742 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? fabiangehrke.eg. (33) 05:12:30.649588 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? fabiangehrke.tz. (33) 05:12:30.653344 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? finenge.lr. (28) 05:12:30.656503 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? freso.mw. (26) 05:12:30.657561 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? floripagolfe.lb. (33) 05:12:30.657932 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? floripagolfe.net.ps. (37) 05:12:30.657996 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? floripagolfe.org.lb. (37) 05:12:30.659987 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? globalmindsit.ps. (34) 05:12:30.660426 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? geralinvestimentos.lb. (39) 05:12:30.660573 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? guiarodas.com.cu. (34) 05:12:30.661202 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? geralinvestimentos.tn. (39) 05:12:30.662106 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? globalmindsit.net.al. (38) 05:12:30.663420 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? icotec.az. (27) 05:12:30.664117 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? guiarodas.org.ps. (34) 05:12:30.665422 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? hogv.net.ps. (29) 05:12:30.667715 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? intellectuale.com.ps. (38) 05:12:30.668505 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? kathrein.net.lb. (33) 05:12:30.669712 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? kdw.net.ps. (28) 05:12:30.670295 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? kathrein.az. (29) 05:12:30.670588 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? kathrein.com.lb. (33) 05:12:30.672045 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? krauchibier.eg. (32) 05:12:30.672119 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? leroyinfo.xn--pgbs0dh. (39) 05:12:30.673693 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? leroyinfo.com.ps. (34) 05:12:30.674500 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? marci.jo. (26) 05:12:30.675054 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? marci.org.ps. (30) 05:12:30.675521 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? lovedrio.mw. (29) 05:12:30.676400 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? marci.az. (26) 05:12:30.678243 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? medicofuncional.sz. (36) 05:12:30.680021 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? medicofuncional.eg. (36) 05:12:30.681171 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? migcomex.sz. (29) 05:12:30.681436 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? meustylo.eg. (29) 05:12:30.681880 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? meustylo.net.ps. (33) 05:12:30.681999 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? nipponengenharia.jo. (37) 05:12:30.682808 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? nipponengenharia.sz. (37) 05:12:30.683166 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? migcomex.jo. (29) 05:12:30.685445 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? prestservi.net.ps. (35) 05:12:30.686534 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? nois.net.ps. (29) 05:12:30.686604 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? psymotion.eg. (30) 05:12:30.687093 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? prestservi.al. (31) 05:12:30.688912 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? psymotion.com.cu. (34) 05:12:30.691537 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? raddarimobiliaria.al. (38) 05:12:30.692317 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? raddarimobiliaria.net.al. (42) 05:12:30.692821 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? raddarimobiliaria.sz. (38) 05:12:30.693708 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.com.al. (42) 05:12:30.693773 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? rastreadortelefonica.mw. (41) 05:12:30.695921 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? revistainterface.net.lb. (41) 05:12:30.696028 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.az. (38) 05:12:30.696257 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? revistainterface.sz. (37) 05:12:30.696769 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.lr. (38) 05:12:30.697003 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.net.lb. (42) 05:12:30.697077 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? rhpinturas.eg. (31) 05:12:30.697148 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.org.al. (42) 05:12:30.698170 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? santacoxinha.az. (33) 05:12:30.699220 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? santacoxinha.org.ps. (37) 05:12:30.699469 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? rhpinturas.com.cu. (35) 05:12:30.702161 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.al. (36) 05:12:30.702428 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? smera.tn. (26) 05:12:30.702810 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.jo. (36) 05:12:30.703163 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.org.al. (40) 05:12:30.703440 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.ps. (36) 05:12:30.704011 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? trespassos.sz. (31) 05:12:30.705183 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? smera.xn--pgbs0dh. (35) 05:12:30.707882 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? zanzo.sz. (26) 05:12:30.711762 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? entria.eg. (27) 05:12:30.716565 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? huotilaoy.xn--mgbayh7gpa. (42) 05:12:30.721220 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? kosketusnaytto.jo. (35) 05:12:30.721321 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? kosketusnaytto.lr. (35) 05:12:30.725011 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? nordicrent.sz. (31) 05:12:30.725020 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? nordicrent.ps. (31) 05:12:30.727057 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? ssjatehuolto.com.al. (37) 05:12:30.727502 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? volkswagen-crafter.com.al. (43) 05:12:30.729899 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? xn--alasenmkit-kcb.org.al. (43) 05:12:30.730896 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? volkswagen-crafter.org.al. (43) 05:12:30.730906 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? volkswagen-crafter.org.lb. (43) 05:12:30.731448 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? xn--myymlsiivous-jcbb.ps. (42) 05:12:30.732235 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? xn--alasenmkit-kcb.net.al. (43) 05:12:30.733062 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? xn--myymlsiivous-jcbb.com.al. (46) 05:12:30.735608 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? 17ice.tn. (26) 05:12:30.735613 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? 17ice.tz. (26) 05:12:30.736906 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? 100man.org.lb. (31) 05:12:30.739163 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? adatarafureai-c.com.lb. (40) 05:12:30.744438 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? asunaro-douro.com.ps. (38) 05:12:30.744551 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? artistlife.ps. (31) 05:12:30.744862 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? artistlife.xn--pgbs0dh. (40) 05:12:30.746378 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? asa-yota.xn--mgbayh7gpa. (41) 05:12:30.748170 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? atabey.az. (27) 05:12:30.748600 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? auntstella.xn--pgbs0dh. (40) 05:12:30.749607 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? ay-renga.net.ps. (33) 05:12:30.750278 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? baci.az. (25) 05:12:30.751657 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? baci.xn--mgbayh7gpa. (37) 05:12:30.752126 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? ay-renga.net.al. (33) 05:12:30.753779 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? baci.org.al. (29) 05:12:30.755331 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? bebe.org.al. (29) 05:12:30.755397 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? c-bars.cu. (27) 05:12:30.757890 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? c-bars.eg. (27) 05:12:30.759854 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? onlyforwomen.cu. (33) 05:12:30.760715 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? onlyforwomen.sz. (33) 05:12:30.760863 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? sandkilde.com.ps. (34) 05:12:30.761027 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? sandkilde.eg. (30) 05:12:30.762050 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? sandkilde.xn--pgbs0dh. (39) 05:12:30.763435 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? nehrmann.net.ps. (33) 05:12:30.764433 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? marineair.net.lb. (34) 05:12:30.764781 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? photos78.net.al. (33) 05:12:30.766487 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? stihl-timbersports.net.lb. (43) 05:12:30.766803 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? stihl-timbersports.org.ps. (43) 05:12:30.768185 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? varmepumpe-konsulenten.net.ps. (47) 05:12:30.768296 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? varmepumpe-konsulenten.org.lb. (47) 05:12:30.768409 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? stihl-timbersports.com.cu. (43) 05:12:30.771863 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? socialhumanisme.al. (36) 05:12:30.772796 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? socialhumanisme.org.al. (40) 05:12:30.773014 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? vikingbartender.com.cu. (40) 05:12:30.773195 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? vikingbartender.com.ps. (40) 05:12:30.773982 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? qr-app.lb. (27) 05:12:30.775106 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? translationteam-online.com.ps. (47) 05:12:30.775619 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? socialhumanisme.tz. (36) 05:12:30.776549 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? pippihuset.com.al. (35) 05:12:30.776976 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? qr-app.sz. (27) 05:12:30.779125 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? midtvestbredbaand.tn. (38) 05:12:30.780127 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? pippihuset.sz. (31) 05:12:30.781822 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? midtvestbredbaand.xn--pgbs0dh. (47) 05:12:30.782815 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? outdoor-xplore.org.al. (39) 05:12:30.783189 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? outdoor-xplore.tz. (35) 05:12:30.784112 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? oborulf.net.al. (32) 05:12:30.784419 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? oborulf.org.al. (32) 05:12:30.784500 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? u-portal.lb. (29) 05:12:30.784624 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? oborulf.sz. (28) 05:12:30.786165 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? sommerly.xn--mgbayh7gpa. (41) 05:12:30.787734 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? u-portal.sz. (29) 05:12:30.789667 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? sorensenrasmus.cu. (35) 05:12:30.790147 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? xn--brneinfoen-0cb.com.al. (43) 05:12:30.791114 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? stentegaarden.com.ps. (38) 05:12:30.791330 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? stentegaarden.eg. (34) 05:12:30.792246 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? mikkmakk.org.lb. (33) 05:12:30.792836 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? xn--brneinfoen-0cb.eg. (39) 05:12:30.793296 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? mitbryllup.lb. (31) 05:12:30.793778 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? mikkmakk.az. (29) 05:12:30.794112 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? mikkmakk.com.ps. (33) 05:12:30.794477 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? mikkmakk.net.al. (33) 05:12:30.795167 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? mikkmakk.xn--pgbs0dh. (38) 05:12:30.795471 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? mitbryllup.com.al. (35) 05:12:30.796033 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? susannekloster.cu. (35) 05:12:30.796545 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? mitbryllup.sz. (31) 05:12:30.797734 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? mibaja.org.al. (31) 05:12:30.798218 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? mibaja.tz. (27) 05:12:30.799161 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? retssamarbejde.com.lb. (39) 05:12:30.800905 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? philippe.org.ps. (33) 05:12:30.803834 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? smede-gaarden.jo. (34) 05:12:30.806905 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.lb. (40) 05:12:30.807117 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.net.lb. (44) 05:12:30.807465 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.tn. (40) 05:12:30.807578 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.xn--mgbayh7gpa. (52) 05:12:30.810550 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? poolfodbold.jo. (32) 05:12:30.810712 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? poolfodbold.net.al. (36) 05:12:30.812223 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? rav-vaerkstedet.sz. (36) 05:12:30.812227 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? rav-vaerkstedet.xn--mgbayh7gpa. (48) 05:12:30.813134 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? succestv.com.al. (33) 05:12:30.814769 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? tbmfotografi.net.ps. (37) 05:12:30.816632 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? succestv.ps. (29) 05:12:30.817089 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? violetcasino.tz. (33) 05:12:30.821192 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? ledstivhed.tz. (31) 05:12:30.821928 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? madogrikke.jo. (31) 05:12:30.823876 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? locksmith.org.al. (34) 05:12:30.824331 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? seniorpm.org.al. (33) 05:12:30.826568 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? seniorpm.lr. (29) 05:12:30.827126 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? seniorpm.tn. (29) 05:12:30.828655 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? trommerum.tz. (30) 05:12:30.830463 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? mrosted.sz. (28) 05:12:30.830718 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? shop-radiocom.com.ps. (38) 05:12:30.831924 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? marialevy.tz. (30) 05:12:30.832169 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.al. (35) 05:12:30.832734 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.jo. (35) 05:12:30.833091 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.org.al. (39) 05:12:30.833226 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? marialevy.az. (30) 05:12:30.833260 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.ps. (35) 05:12:30.833862 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? marialevy.mw. (30) 05:12:30.837978 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? perjorgensen.com.al. (37) 05:12:30.839772 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? petrotec.eg. (29) 05:12:30.840564 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? petrotec.sz. (29) 05:12:30.840935 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? tedi-inu.org.al. (33) 05:12:30.841593 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? strapshop.jo. (30) 05:12:30.842109 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? strapshop.sz. (30) 05:12:30.842874 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? tedi-inu.eg. (29) 05:12:30.843499 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? tedi-inu.org.lb. (33) 05:12:30.844171 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? hotelportodimare.sz. (37) 05:12:30.845392 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? xn--slgtsportalen-4fb.net.al. (46) 05:12:30.846506 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? hotelportodimare.org.al. (41) 05:12:30.846989 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? xn--fldebollen-1cb.org.lb. (43) 05:12:30.847210 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? xn--fldebollen-1cb.sz. (39) 05:12:30.848228 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? ecologiccar.mw. (32) 05:12:30.848805 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? xn--fldebollen-1cb.eg. (39) 05:12:30.850883 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? ecologiccar.net.ps. (36) 05:12:30.851589 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? agenciaape.org.al. (35) 05:12:30.852787 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? revistapreview.org.ps. (39) 05:12:30.853568 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? precodagasolina.xn--pgbs0dh. (45) 05:12:30.855193 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? editorareviva.com.al. (38) 05:12:30.856465 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? editorareviva.xn--pgbs0dh. (43) 05:12:30.857136 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? ganhoscertos.lr. (33) 05:12:30.859411 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? xn--furesbibliotekerne-k4b.tn. (47) 05:12:30.859993 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? ganhoscertos.net.ps. (37) 05:12:30.860369 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? ganhoscertos.ps. (33) 05:12:30.860524 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? xn--furesbibliotekerne-k4b.al. (47) 05:12:30.861657 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? xn--furesbibliotekerne-k4b.org.al. (51) 05:12:30.862863 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? xn--lsningtagogisolering-bcc.lb. (49) 05:12:30.865140 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? newways-vix.az. (32) 05:12:30.865699 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? betterresidencias.al. (38) 05:12:30.866468 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? newways-vix.tz. (32) 05:12:30.866626 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? newways-vix.xn--mgbayh7gpa. (44) 05:12:30.867104 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? elymartins.eg. (31) 05:12:30.868766 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? curitibahostel.xn--mgbayh7gpa. (47) 05:12:30.869020 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? betterresidencias.net.al. (42) 05:12:30.869950 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? curitibahostel.com.cu. (39) 05:12:30.870401 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? xpenditure.az. (31) 05:12:30.873222 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? xpenditure.com.lb. (35) 05:12:30.873737 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? agenciamarcospontes.com.al. (44) 05:12:30.877058 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? agenciamarcospontes.org.al. (44) 05:12:30.877167 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? agenciamarcospontes.org.lb. (44) 05:12:30.877368 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? zyngacasino.net.ps. (36) 05:12:30.877883 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? zyngacasino.xn--mgbayh7gpa. (44) 05:12:30.878123 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? xn--kbenhavnsmotorkontor-bcc.lb. (49) 05:12:30.878442 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? xn--kbenhavnsmotorkontor-bcc.org.al. (53) 05:12:30.880982 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? 3fepis.com.ps. (31) 05:12:30.881063 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? 3fepis.cu. (27) 05:12:30.881703 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? adis.mw. (25) 05:12:30.882685 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? calepino.com.cu. (33) 05:12:30.884668 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? adis.ps. (25) 05:12:30.884992 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? biometrix.org.al. (34) 05:12:30.886431 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? artbit.org.lb. (31) 05:12:30.887009 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? facidf.com.cu. (31) 05:12:30.888423 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? artbit.com.ps. (31) 05:12:30.889534 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? jet-avionics.xn--pgbs0dh. (42) 05:12:30.889643 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? polotec.al. (28) 05:12:30.891745 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? jet-avionics.org.al. (37) 05:12:30.893141 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? polotec.org.al. (32) 05:12:30.894660 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.eg. (36) 05:12:30.894861 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.lr. (36) 05:12:30.895132 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? concursobestcars.xn--mgbayh7gpa. (49) 05:12:30.895261 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.org.al. (40) 05:12:30.897678 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.net.lb. (40) 05:12:30.898605 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? canalpiloto.tn. (32) 05:12:30.899191 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? fourty.net.lb. (31) 05:12:30.899477 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? fourty.ps. (27) 05:12:30.901820 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? armazemdesonhos.sz. (36) 05:12:30.902337 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? paranacasamentos.org.al. (41) 05:12:30.902377 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? gabrielmedinaoficial.com.al. (45) 05:12:30.904210 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? armazemdesonhos.org.ps. (40) 05:12:30.906449 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? xn--vestfyntrkker-cgb.com.lb. (46) 05:12:30.906534 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? xn--vestfyntrkker-cgb.eg. (42) 05:12:30.908913 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? portalguiapiracicaba.tn. (41) 05:12:30.910018 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? ibopy.org.al. (30) 05:12:30.910652 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? peterbilgrav.org.lb. (37) 05:12:30.911280 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? aplj.net.lb. (29) 05:12:30.912402 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? peterbilgrav.com.ps. (37) 05:12:30.912617 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? peterbilgrav.jo. (33) 05:12:30.913366 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? phoyer.net.lb. (31) 05:12:30.913975 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? phoejager.com.ps. (34) 05:12:30.918513 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? pmk.eg. (24) 05:12:30.919327 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? pmk.ps. (24) 05:12:30.919728 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? pmvinduespolering.com.al. (42) 05:12:30.920403 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? pmvinduespolering.lb. (38) 05:12:30.921196 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? prazsky-krysarik.ps. (37) 05:12:30.924348 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? privatrengoring.com.al. (40) 05:12:30.925556 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? privatrengoring.sz. (36) 05:12:30.927278 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? proces-manager.sz. (35) 05:12:30.928604 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? ramentobiiru.lr. (33) 05:12:30.931413 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? ramentobiiru.org.al. (37) 05:12:30.931977 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? randersbutikker.al. (36) 05:12:30.932049 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? redwheels.ps. (30) 05:12:30.932400 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? redwheels.xn--pgbs0dh. (39) 05:12:30.932625 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? randersbutikker.lr. (36) 05:12:30.934344 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? redwheels.net.al. (34) 05:12:30.934423 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? restaurantguider.eg. (37) 05:12:30.935494 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? retrofjer.az. (30) 05:12:30.935605 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? restaurant-kolding.lr. (39) 05:12:30.935612 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? restaurant-kolding.net.lb. (43) 05:12:30.935890 IP 193.235.141.125.32768 > 666.42.7.11.53: 14 NS? retrofjer.cu. (30) 05:12:30.936973 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? retrospective.al. (34) 05:12:30.939311 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? rexfelt.net.al. (32) 05:12:30.941402 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? rexfelt.com.lb. (32) 05:12:30.942557 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? rincon.al. (27) 05:12:30.942784 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? rincon.com.al. (31) 05:12:30.942945 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? rincon.eg. (27) 05:12:30.944302 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? s-t-a-r.com.al. (32) 05:12:30.945846 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? salonchristy.tn. (33) 05:12:30.946792 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? sammenkomst.mw. (32) 05:12:30.947019 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? salonchristy.al. (33) 05:12:30.947558 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? scandinavianantiques.al. (41) 05:12:30.948872 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? scandinavianantiques.sz. (41) 05:12:30.949380 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? sammenkomst.net.al. (36) 05:12:30.951069 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? scandinavianantiques.org.al. (45) 05:12:30.951304 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? scansani.lr. (29) 05:12:30.952391 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? scandinavianhospitalitysolutions.lr. (53) 05:12:30.953024 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? se-br.lb. (26) 05:12:30.954721 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? semlershop.net.al. (35) 05:12:30.956497 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? semlershop.az. (31) 05:12:30.956595 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? semlershop.com.al. (35) 05:12:30.956653 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? semlershop.com.cu. (35) 05:12:30.957505 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.lr. (34) 05:12:30.957816 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? semlershop.tz. (31) 05:12:30.958134 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.tz. (34) 05:12:30.959803 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.com.lb. (38) 05:12:30.960044 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.lb. (34) 05:12:30.960504 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.org.al. (38) 05:12:30.960609 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? smaagaver.net.ps. (34) 05:12:30.963373 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? snakspillet.lr. (32) 05:12:30.964082 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? smsfun.cu. (27) 05:12:30.965011 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? snowlab.net.al. (32) 05:12:30.967171 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? socialdebatten.ps. (35) 05:12:30.967788 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? snowlab.net.ps. (32) 05:12:30.968312 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? spapakker.net.al. (34) 05:12:30.971803 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? starstorm.tz. (30) 05:12:30.971864 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? spillefeltet.com.ps. (37) 05:12:30.972227 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? spillefeltet.lr. (33) 05:12:30.974248 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? stuhrcompagniet.lr. (36) 05:12:30.974497 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? strandparken-beboerforening.al. (48) 05:12:30.974819 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? stuhrcompagniet.sz. (36) 05:12:30.975853 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? sukkertand.net.al. (35) 05:12:30.975943 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? strandparken-beboerforening.xn--mgbayh7gpa. (60) 05:12:30.977050 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? stuhrcompagniet.net.lb. (40) 05:12:30.977354 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? sund-i-psyken.net.lb. (38) 05:12:30.978420 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? sukkertand.mw. (31) 05:12:30.978686 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? sund-rejser.lb. (32) 05:12:30.978793 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? sund-rejser.net.al. (36) 05:12:30.980401 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? sund-i-psyken.tn. (34) 05:12:30.980439 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? svanebogholderen.org.al. (41) 05:12:30.980844 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? sund-rejser.com.lb. (36) 05:12:30.981115 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? svarre-hansen.al. (34) 05:12:30.982654 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? svanebogholderen.lr. (37) 05:12:30.986394 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? svinedrengen.ps. (33) 05:12:30.986823 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? swed-mart.sz. (30) 05:12:30.988072 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? svingteknik.xn--mgbayh7gpa. (44) 05:12:30.989526 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? swed-mart.xn--mgbayh7gpa. (42) 05:12:30.989642 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? symedglaede.al. (32) 05:12:30.989786 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? teamferritslev.tn. (35) 05:12:30.990684 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? symedglaede.org.al. (36) 05:12:30.990823 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? teamjohn.net.al. (33) 05:12:30.993586 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? tilbudsapps.eg. (32) 05:12:30.994202 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? testsommerhus.al. (34) 05:12:30.994430 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? testsommerhus.com.ps. (38) 05:12:30.997887 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? toemrermester-larsgyde.lb. (43) 05:12:30.999061 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? toftevej12.eg. (31) 05:12:31.001566 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? tpfrb.tz. (26) 05:12:31.001864 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? trbeton.org.lb. (32) 05:12:31.002217 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? turo4.az. (26) 05:12:31.004424 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? trbeton.ps. (28) 05:12:31.004887 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? turo4.com.lb. (30) 05:12:31.007499 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? unikboligadministration.sz. (44) 05:12:31.008907 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? vaerum.org.ps. (31) 05:12:31.009252 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? vaerum.xn--pgbs0dh. (36) 05:12:31.009586 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? varebilmagasinet.com.lb. (41) 05:12:31.011616 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? veteranbil-mc.net.al. (38) 05:12:31.014456 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? vikogwok.mw. (29) 05:12:31.015144 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? vinkelagerbo.al. (33) 05:12:31.017745 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? visiblepr.org.lb. (34) 05:12:31.019530 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? xn--brnehavenkastaniehuset-5ic.net.al. (55) 05:12:31.020055 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? xn--brnehavenkastaniehuset-5ic.tz. (51) 05:12:31.020458 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? xn--finddkcenter-bdb.com.al. (45) 05:12:31.021672 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? xn--brnehavenkastaniehuset-5ic.cu. (51) 05:12:31.023179 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? xn--finddkcenter-bdb.eg. (41) 05:12:31.024574 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? xn--lvgreen-byg-ggb.sz. (40) 05:12:31.026630 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? xn--lvgreen-byg-ggb.lr. (40) 05:12:31.026703 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? xn--nrregaardadvokatfirma-qfc.eg. (50) 05:12:31.027543 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? xn--nrregaardadvokatfirma-qfc.tz. (50) 05:12:31.028150 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.eg. (41) 05:12:31.028757 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.mw. (41) 05:12:31.028804 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.net.ps. (45) 05:12:31.029183 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.tn. (41) 05:12:31.029912 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? xn--nrregaardadvokatfirma-qfc.org.al. (54) 05:12:31.031014 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? zebra-avisen.az. (33) 05:12:31.032044 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? xn--sbolde-bya.az. (35) 05:12:31.033085 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? xn--sbolde-bya.org.ps. (39) 05:12:31.033111 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? adderehub.net.lb. (34) 05:12:31.034472 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? alkes.lr. (26) 05:12:31.034584 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? alkes.net.al. (30) 05:12:31.034893 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? alkes.org.ps. (30) 05:12:31.035227 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? alkes.xn--mgbayh7gpa. (38) 05:12:31.035462 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? arteepropaganda.com.al. (40) 05:12:31.035638 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? adderehub.lb. (30) 05:12:31.036486 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? alkes.az. (26) 05:12:31.037894 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? assistenteonline.org.al. (41) 05:12:31.038307 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? arteepropaganda.eg. (36) 05:12:31.039532 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? assistenteonline.az. (37) 05:12:31.041160 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? avprolamentos.com.cu. (38) 05:12:31.041287 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? avprolamentos.eg. (34) 05:12:31.044035 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? bardompedro.al. (32) 05:12:31.044238 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? bardompedro.com.cu. (36) 05:12:31.045990 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? bradescompletonline.al. (40) 05:12:31.047418 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? clipcomunicacao.az. (36) 05:12:31.050820 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? criativasoft.cu. (33) 05:12:31.051099 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? criativasoft.jo. (33) 05:12:31.051260 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? clipcomunicacao.tz. (36) 05:12:31.051328 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? clipcomunicacao.xn--pgbs0dh. (45) 05:12:31.054433 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? desciclopedia.az. (34) 05:12:31.055795 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? directschool.org.lb. (37) 05:12:31.056389 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? diocesedejales.jo. (35) 05:12:31.060000 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? dlbc.tz. (25) 05:12:31.060842 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? naturheilen.cu. (32) 05:12:31.062017 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? shopwindowstickers.az. (39) 05:12:31.062612 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? shopwindowstickers.net.al. (43) 05:12:31.064165 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? domfinder.lr. (30) 05:12:31.066182 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? domfinder.com.cu. (34) 05:12:31.066612 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? domfinder.lb. (30) 05:12:31.069057 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? sagrimatel.al. (31) 05:12:31.070182 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? flodqvist.lb. (30) 05:12:31.070854 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? flodqvist.sz. (30) 05:12:31.071638 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? rendaonlinetelexfree.org.al. (45)
You missed the point I was trying to make. While I think that that source is trying to enumerate some part of the namespace. NS queries by themselves don’t indicate an attack. Others would probably see the series of NS queries as a signature of an attack when they are NOT. There needs to be much more than that to make that conclusion. -- Mark Andrews
On 2 Nov 2023, at 06:15, Randy Bush <randy@psg.com> wrote:
ya, right, and at a whole bunch of other cctld servers
from a network called domaincrawler-hosting
shall we smoke another?
/home/randy> sudo tcpdump -pni vtnet0 -c 500 port 53 and net 193.235.141 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on vtnet0, link-type EN10MB (Ethernet), capture size 262144 bytes 05:12:30.563268 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? cgatcity.com.cu. (33) 05:12:30.565017 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? christ-jockel.jo. (34) 05:12:30.565660 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? cgatcity.al. (29) 05:12:30.566490 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? cgatcity.org.al. (33) 05:12:30.566694 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? christian-luber-jr.net.al. (43) 05:12:30.569474 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? clearing-muenchen.eg. (38) 05:12:30.571870 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? clearing-muenchen.com.ps. (42) 05:12:30.573436 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? cofls-welt.xn--pgbs0dh. (40) 05:12:30.573914 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? club-lederwerk-neustadt.net.al. (48) 05:12:30.574608 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? cofls-welt.az. (31) 05:12:30.575203 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? cofls-welt.lb. (31) 05:12:30.575356 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? conomix.eg. (28) 05:12:30.575950 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? conomix.net.ps. (32) 05:12:30.577242 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? computercheck-online.tn. (41) 05:12:30.577800 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? conomix.cu. (28) 05:12:30.578272 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? conomix.net.lb. (32) 05:12:30.578480 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? cstreibel.lr. (30) 05:12:30.578896 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? cstreibel.org.lb. (34) 05:12:30.579060 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? cristallcard.az. (33) 05:12:30.580681 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? d-cypher.tn. (29) 05:12:30.581812 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? d-cypher.al. (29) 05:12:30.582157 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? dailycatesse.sz. (33) 05:12:30.582381 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? d-cypher.eg. (29) 05:12:30.583340 IP 193.235.141.125.32768 > 666.42.7.11.53: 14 NS? damensattel-duesseldorf.net.ps. (48) 05:12:30.583439 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? dailycatesse.az. (33) 05:12:30.584078 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? dailycatesse.mw. (33) 05:12:30.584330 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? dailycatesse.org.al. (37) 05:12:30.584730 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? darkroom24.net.al. (35) 05:12:30.585506 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? damensattel-duesseldorf.jo. (44) 05:12:30.585995 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? dassehen.lr. (29) 05:12:30.587759 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? darkroom24.tn. (31) 05:12:30.588076 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? dgurock.org.al. (32) 05:12:30.589055 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? dictys.jo. (27) 05:12:30.589640 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? dgurock.az. (28) 05:12:30.591432 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? dictys.com.ps. (31) 05:12:30.592608 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? disko-thema.org.al. (36) 05:12:30.593365 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? diesling-1.net.al. (35) 05:12:30.593814 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? diesling-1.ps. (31) 05:12:30.595057 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? disko-thema.net.al. (36) 05:12:30.595722 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? disko-thema.xn--mgbayh7gpa. (44) 05:12:30.596496 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? downbeat-band.com.lb. (38) 05:12:30.596898 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? dj-hc-team.sz. (31) 05:12:30.598077 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? dnd-testdomain.net.al. (39) 05:12:30.598203 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? dnd-testdomain.net.ps. (39) 05:12:30.598338 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? druck-hamster.lr. (34) 05:12:30.599224 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? druckerei-hilden.az. (37) 05:12:30.602031 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? druckerei-hilden.com.lb. (41) 05:12:30.604763 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? drumandy.xn--pgbs0dh. (38) 05:12:30.605420 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? dugehoerstmir.tz. (34) 05:12:30.607074 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? dugehoerstmir.eg. (34) 05:12:30.607465 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? dugehoerstmir.net.lb. (38) 05:12:30.608142 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? xn--kostogkrft-k6a.al. (39) 05:12:30.608867 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? xn--rkenvej-p1a.com.al. (40) 05:12:30.610043 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? xn--ombygningsln-3cb.cu. (41) 05:12:30.613031 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? xn--sportholbk-l6a.com.lb. (43) 05:12:30.613510 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? xn--sportholbk-l6a.mw. (39) 05:12:30.613660 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? xn--sportholbk-l6a.net.ps. (43) 05:12:30.613911 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? yumlife.lr. (28) 05:12:30.614575 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? yumlife.tn. (28) 05:12:30.615677 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? yumlife.al. (28) 05:12:30.616176 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? yumlife.cu. (28) 05:12:30.617347 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? zensolutions.az. (33) 05:12:30.619396 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? zonebente.jo. (30) 05:12:30.620738 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? acas.com.lb. (29) 05:12:30.620884 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? acomacoestepr.al. (34) 05:12:30.621900 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? acere.az. (26) 05:12:30.622118 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? acomacoestepr.sz. (34) 05:12:30.622755 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? acere.net.ps. (30) 05:12:30.623809 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? alfamob.al. (28) 05:12:30.624673 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? acomacoestepr.xn--mgbayh7gpa. (46) 05:12:30.624943 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? aeerj.az. (26) 05:12:30.624962 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? alfamob.org.lb. (32) 05:12:30.625567 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? aeerj.lr. (26) 05:12:30.626919 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? amao.az. (25) 05:12:30.627264 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? alfamob.net.ps. (32) 05:12:30.628910 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? alemdaideia.net.ps. (36) 05:12:30.629337 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? alemdaideia.tn. (32) 05:12:30.629996 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? aparelhodigestivo.xn--pgbs0dh. (47) 05:12:30.630926 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? artvenite.net.lb. (34) 05:12:30.631583 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? belemportal.al. (32) 05:12:30.631608 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? aparelhodigestivo.eg. (38) 05:12:30.633330 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? artvenite.lr. (30) 05:12:30.635616 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? belemportal.xn--pgbs0dh. (41) 05:12:30.637710 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? cassiturismo.az. (33) 05:12:30.639069 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? cassiturismo.sz. (33) 05:12:30.639311 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? cartolinadesign.lr. (36) 05:12:30.639724 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? cerimonialmariah.eg. (37) 05:12:30.640816 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? cassiturismo.jo. (33) 05:12:30.640892 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? cassiturismo.lr. (33) 05:12:30.641266 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? colegioiguacu.jo. (34) 05:12:30.641496 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? colegioiguacu.net.al. (38) 05:12:30.642908 IP 193.235.141.125.32768 > 666.42.7.11.53: 14 NS? conceitorio.lr. (32) 05:12:30.646825 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? csrb.lb. (25) 05:12:30.647078 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? doceriaexpress.com.ps. (39) 05:12:30.648381 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? fabiangehrke.com.al. (37) 05:12:30.648742 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? fabiangehrke.eg. (33) 05:12:30.649588 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? fabiangehrke.tz. (33) 05:12:30.653344 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? finenge.lr. (28) 05:12:30.656503 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? freso.mw. (26) 05:12:30.657561 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? floripagolfe.lb. (33) 05:12:30.657932 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? floripagolfe.net.ps. (37) 05:12:30.657996 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? floripagolfe.org.lb. (37) 05:12:30.659987 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? globalmindsit.ps. (34) 05:12:30.660426 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? geralinvestimentos.lb. (39) 05:12:30.660573 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? guiarodas.com.cu. (34) 05:12:30.661202 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? geralinvestimentos.tn. (39) 05:12:30.662106 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? globalmindsit.net.al. (38) 05:12:30.663420 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? icotec.az. (27) 05:12:30.664117 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? guiarodas.org.ps. (34) 05:12:30.665422 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? hogv.net.ps. (29) 05:12:30.667715 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? intellectuale.com.ps. (38) 05:12:30.668505 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? kathrein.net.lb. (33) 05:12:30.669712 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? kdw.net.ps. (28) 05:12:30.670295 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? kathrein.az. (29) 05:12:30.670588 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? kathrein.com.lb. (33) 05:12:30.672045 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? krauchibier.eg. (32) 05:12:30.672119 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? leroyinfo.xn--pgbs0dh. (39) 05:12:30.673693 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? leroyinfo.com.ps. (34) 05:12:30.674500 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? marci.jo. (26) 05:12:30.675054 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? marci.org.ps. (30) 05:12:30.675521 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? lovedrio.mw. (29) 05:12:30.676400 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? marci.az. (26) 05:12:30.678243 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? medicofuncional.sz. (36) 05:12:30.680021 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? medicofuncional.eg. (36) 05:12:30.681171 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? migcomex.sz. (29) 05:12:30.681436 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? meustylo.eg. (29) 05:12:30.681880 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? meustylo.net.ps. (33) 05:12:30.681999 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? nipponengenharia.jo. (37) 05:12:30.682808 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? nipponengenharia.sz. (37) 05:12:30.683166 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? migcomex.jo. (29) 05:12:30.685445 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? prestservi.net.ps. (35) 05:12:30.686534 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? nois.net.ps. (29) 05:12:30.686604 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? psymotion.eg. (30) 05:12:30.687093 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? prestservi.al. (31) 05:12:30.688912 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? psymotion.com.cu. (34) 05:12:30.691537 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? raddarimobiliaria.al. (38) 05:12:30.692317 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? raddarimobiliaria.net.al. (42) 05:12:30.692821 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? raddarimobiliaria.sz. (38) 05:12:30.693708 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.com.al. (42) 05:12:30.693773 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? rastreadortelefonica.mw. (41) 05:12:30.695921 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? revistainterface.net.lb. (41) 05:12:30.696028 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.az. (38) 05:12:30.696257 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? revistainterface.sz. (37) 05:12:30.696769 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.lr. (38) 05:12:30.697003 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.net.lb. (42) 05:12:30.697077 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? rhpinturas.eg. (31) 05:12:30.697148 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? restaurantesakura.org.al. (42) 05:12:30.698170 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? santacoxinha.az. (33) 05:12:30.699220 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? santacoxinha.org.ps. (37) 05:12:30.699469 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? rhpinturas.com.cu. (35) 05:12:30.702161 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.al. (36) 05:12:30.702428 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? smera.tn. (26) 05:12:30.702810 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.jo. (36) 05:12:30.703163 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.org.al. (40) 05:12:30.703440 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? silvanacalvetti.ps. (36) 05:12:30.704011 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? trespassos.sz. (31) 05:12:30.705183 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? smera.xn--pgbs0dh. (35) 05:12:30.707882 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? zanzo.sz. (26) 05:12:30.711762 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? entria.eg. (27) 05:12:30.716565 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? huotilaoy.xn--mgbayh7gpa. (42) 05:12:30.721220 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? kosketusnaytto.jo. (35) 05:12:30.721321 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? kosketusnaytto.lr. (35) 05:12:30.725011 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? nordicrent.sz. (31) 05:12:30.725020 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? nordicrent.ps. (31) 05:12:30.727057 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? ssjatehuolto.com.al. (37) 05:12:30.727502 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? volkswagen-crafter.com.al. (43) 05:12:30.729899 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? xn--alasenmkit-kcb.org.al. (43) 05:12:30.730896 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? volkswagen-crafter.org.al. (43) 05:12:30.730906 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? volkswagen-crafter.org.lb. (43) 05:12:30.731448 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? xn--myymlsiivous-jcbb.ps. (42) 05:12:30.732235 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? xn--alasenmkit-kcb.net.al. (43) 05:12:30.733062 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? xn--myymlsiivous-jcbb.com.al. (46) 05:12:30.735608 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? 17ice.tn. (26) 05:12:30.735613 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? 17ice.tz. (26) 05:12:30.736906 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? 100man.org.lb. (31) 05:12:30.739163 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? adatarafureai-c.com.lb. (40) 05:12:30.744438 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? asunaro-douro.com.ps. (38) 05:12:30.744551 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? artistlife.ps. (31) 05:12:30.744862 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? artistlife.xn--pgbs0dh. (40) 05:12:30.746378 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? asa-yota.xn--mgbayh7gpa. (41) 05:12:30.748170 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? atabey.az. (27) 05:12:30.748600 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? auntstella.xn--pgbs0dh. (40) 05:12:30.749607 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? ay-renga.net.ps. (33) 05:12:30.750278 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? baci.az. (25) 05:12:30.751657 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? baci.xn--mgbayh7gpa. (37) 05:12:30.752126 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? ay-renga.net.al. (33) 05:12:30.753779 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? baci.org.al. (29) 05:12:30.755331 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? bebe.org.al. (29) 05:12:30.755397 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? c-bars.cu. (27) 05:12:30.757890 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? c-bars.eg. (27) 05:12:30.759854 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? onlyforwomen.cu. (33) 05:12:30.760715 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? onlyforwomen.sz. (33) 05:12:30.760863 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? sandkilde.com.ps. (34) 05:12:30.761027 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? sandkilde.eg. (30) 05:12:30.762050 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? sandkilde.xn--pgbs0dh. (39) 05:12:30.763435 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? nehrmann.net.ps. (33) 05:12:30.764433 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? marineair.net.lb. (34) 05:12:30.764781 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? photos78.net.al. (33) 05:12:30.766487 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? stihl-timbersports.net.lb. (43) 05:12:30.766803 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? stihl-timbersports.org.ps. (43) 05:12:30.768185 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? varmepumpe-konsulenten.net.ps. (47) 05:12:30.768296 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? varmepumpe-konsulenten.org.lb. (47) 05:12:30.768409 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? stihl-timbersports.com.cu. (43) 05:12:30.771863 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? socialhumanisme.al. (36) 05:12:30.772796 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? socialhumanisme.org.al. (40) 05:12:30.773014 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? vikingbartender.com.cu. (40) 05:12:30.773195 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? vikingbartender.com.ps. (40) 05:12:30.773982 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? qr-app.lb. (27) 05:12:30.775106 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? translationteam-online.com.ps. (47) 05:12:30.775619 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? socialhumanisme.tz. (36) 05:12:30.776549 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? pippihuset.com.al. (35) 05:12:30.776976 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? qr-app.sz. (27) 05:12:30.779125 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? midtvestbredbaand.tn. (38) 05:12:30.780127 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? pippihuset.sz. (31) 05:12:30.781822 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? midtvestbredbaand.xn--pgbs0dh. (47) 05:12:30.782815 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? outdoor-xplore.org.al. (39) 05:12:30.783189 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? outdoor-xplore.tz. (35) 05:12:30.784112 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? oborulf.net.al. (32) 05:12:30.784419 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? oborulf.org.al. (32) 05:12:30.784500 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? u-portal.lb. (29) 05:12:30.784624 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? oborulf.sz. (28) 05:12:30.786165 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? sommerly.xn--mgbayh7gpa. (41) 05:12:30.787734 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? u-portal.sz. (29) 05:12:30.789667 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? sorensenrasmus.cu. (35) 05:12:30.790147 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? xn--brneinfoen-0cb.com.al. (43) 05:12:30.791114 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? stentegaarden.com.ps. (38) 05:12:30.791330 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? stentegaarden.eg. (34) 05:12:30.792246 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? mikkmakk.org.lb. (33) 05:12:30.792836 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? xn--brneinfoen-0cb.eg. (39) 05:12:30.793296 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? mitbryllup.lb. (31) 05:12:30.793778 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? mikkmakk.az. (29) 05:12:30.794112 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? mikkmakk.com.ps. (33) 05:12:30.794477 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? mikkmakk.net.al. (33) 05:12:30.795167 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? mikkmakk.xn--pgbs0dh. (38) 05:12:30.795471 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? mitbryllup.com.al. (35) 05:12:30.796033 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? susannekloster.cu. (35) 05:12:30.796545 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? mitbryllup.sz. (31) 05:12:30.797734 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? mibaja.org.al. (31) 05:12:30.798218 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? mibaja.tz. (27) 05:12:30.799161 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? retssamarbejde.com.lb. (39) 05:12:30.800905 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? philippe.org.ps. (33) 05:12:30.803834 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? smede-gaarden.jo. (34) 05:12:30.806905 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.lb. (40) 05:12:30.807117 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.net.lb. (44) 05:12:30.807465 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.tn. (40) 05:12:30.807578 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? vejentilfiskenettet.xn--mgbayh7gpa. (52) 05:12:30.810550 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? poolfodbold.jo. (32) 05:12:30.810712 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? poolfodbold.net.al. (36) 05:12:30.812223 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? rav-vaerkstedet.sz. (36) 05:12:30.812227 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? rav-vaerkstedet.xn--mgbayh7gpa. (48) 05:12:30.813134 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? succestv.com.al. (33) 05:12:30.814769 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? tbmfotografi.net.ps. (37) 05:12:30.816632 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? succestv.ps. (29) 05:12:30.817089 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? violetcasino.tz. (33) 05:12:30.821192 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? ledstivhed.tz. (31) 05:12:30.821928 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? madogrikke.jo. (31) 05:12:30.823876 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? locksmith.org.al. (34) 05:12:30.824331 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? seniorpm.org.al. (33) 05:12:30.826568 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? seniorpm.lr. (29) 05:12:30.827126 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? seniorpm.tn. (29) 05:12:30.828655 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? trommerum.tz. (30) 05:12:30.830463 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? mrosted.sz. (28) 05:12:30.830718 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? shop-radiocom.com.ps. (38) 05:12:30.831924 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? marialevy.tz. (30) 05:12:30.832169 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.al. (35) 05:12:30.832734 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.jo. (35) 05:12:30.833091 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.org.al. (39) 05:12:30.833226 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? marialevy.az. (30) 05:12:30.833260 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? mortenlundberg.ps. (35) 05:12:30.833862 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? marialevy.mw. (30) 05:12:30.837978 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? perjorgensen.com.al. (37) 05:12:30.839772 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? petrotec.eg. (29) 05:12:30.840564 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? petrotec.sz. (29) 05:12:30.840935 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? tedi-inu.org.al. (33) 05:12:30.841593 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? strapshop.jo. (30) 05:12:30.842109 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? strapshop.sz. (30) 05:12:30.842874 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? tedi-inu.eg. (29) 05:12:30.843499 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? tedi-inu.org.lb. (33) 05:12:30.844171 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? hotelportodimare.sz. (37) 05:12:30.845392 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? xn--slgtsportalen-4fb.net.al. (46) 05:12:30.846506 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? hotelportodimare.org.al. (41) 05:12:30.846989 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? xn--fldebollen-1cb.org.lb. (43) 05:12:30.847210 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? xn--fldebollen-1cb.sz. (39) 05:12:30.848228 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? ecologiccar.mw. (32) 05:12:30.848805 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? xn--fldebollen-1cb.eg. (39) 05:12:30.850883 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? ecologiccar.net.ps. (36) 05:12:30.851589 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? agenciaape.org.al. (35) 05:12:30.852787 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? revistapreview.org.ps. (39) 05:12:30.853568 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? precodagasolina.xn--pgbs0dh. (45) 05:12:30.855193 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? editorareviva.com.al. (38) 05:12:30.856465 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? editorareviva.xn--pgbs0dh. (43) 05:12:30.857136 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? ganhoscertos.lr. (33) 05:12:30.859411 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? xn--furesbibliotekerne-k4b.tn. (47) 05:12:30.859993 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? ganhoscertos.net.ps. (37) 05:12:30.860369 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? ganhoscertos.ps. (33) 05:12:30.860524 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? xn--furesbibliotekerne-k4b.al. (47) 05:12:30.861657 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? xn--furesbibliotekerne-k4b.org.al. (51) 05:12:30.862863 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? xn--lsningtagogisolering-bcc.lb. (49) 05:12:30.865140 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? newways-vix.az. (32) 05:12:30.865699 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? betterresidencias.al. (38) 05:12:30.866468 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? newways-vix.tz. (32) 05:12:30.866626 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? newways-vix.xn--mgbayh7gpa. (44) 05:12:30.867104 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? elymartins.eg. (31) 05:12:30.868766 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? curitibahostel.xn--mgbayh7gpa. (47) 05:12:30.869020 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? betterresidencias.net.al. (42) 05:12:30.869950 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? curitibahostel.com.cu. (39) 05:12:30.870401 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? xpenditure.az. (31) 05:12:30.873222 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? xpenditure.com.lb. (35) 05:12:30.873737 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? agenciamarcospontes.com.al. (44) 05:12:30.877058 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? agenciamarcospontes.org.al. (44) 05:12:30.877167 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? agenciamarcospontes.org.lb. (44) 05:12:30.877368 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? zyngacasino.net.ps. (36) 05:12:30.877883 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? zyngacasino.xn--mgbayh7gpa. (44) 05:12:30.878123 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? xn--kbenhavnsmotorkontor-bcc.lb. (49) 05:12:30.878442 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? xn--kbenhavnsmotorkontor-bcc.org.al. (53) 05:12:30.880982 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? 3fepis.com.ps. (31) 05:12:30.881063 IP 193.235.141.142.32768 > 666.42.7.11.53: 14 NS? 3fepis.cu. (27) 05:12:30.881703 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? adis.mw. (25) 05:12:30.882685 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? calepino.com.cu. (33) 05:12:30.884668 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? adis.ps. (25) 05:12:30.884992 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? biometrix.org.al. (34) 05:12:30.886431 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? artbit.org.lb. (31) 05:12:30.887009 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? facidf.com.cu. (31) 05:12:30.888423 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? artbit.com.ps. (31) 05:12:30.889534 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? jet-avionics.xn--pgbs0dh. (42) 05:12:30.889643 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? polotec.al. (28) 05:12:30.891745 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? jet-avionics.org.al. (37) 05:12:30.893141 IP 193.235.141.134.32768 > 666.42.7.11.53: 14 NS? polotec.org.al. (32) 05:12:30.894660 IP 193.235.141.23.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.eg. (36) 05:12:30.894861 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.lr. (36) 05:12:30.895132 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? concursobestcars.xn--mgbayh7gpa. (49) 05:12:30.895261 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.org.al. (40) 05:12:30.897678 IP 193.235.141.181.32768 > 666.42.7.11.53: 14 NS? rededecarreiras.net.lb. (40) 05:12:30.898605 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? canalpiloto.tn. (32) 05:12:30.899191 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? fourty.net.lb. (31) 05:12:30.899477 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? fourty.ps. (27) 05:12:30.901820 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? armazemdesonhos.sz. (36) 05:12:30.902337 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? paranacasamentos.org.al. (41) 05:12:30.902377 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? gabrielmedinaoficial.com.al. (45) 05:12:30.904210 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? armazemdesonhos.org.ps. (40) 05:12:30.906449 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? xn--vestfyntrkker-cgb.com.lb. (46) 05:12:30.906534 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? xn--vestfyntrkker-cgb.eg. (42) 05:12:30.908913 IP 193.235.141.183.32768 > 666.42.7.11.53: 14 NS? portalguiapiracicaba.tn. (41) 05:12:30.910018 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? ibopy.org.al. (30) 05:12:30.910652 IP 193.235.141.171.32768 > 666.42.7.11.53: 14 NS? peterbilgrav.org.lb. (37) 05:12:30.911280 IP 193.235.141.185.32768 > 666.42.7.11.53: 14 NS? aplj.net.lb. (29) 05:12:30.912402 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? peterbilgrav.com.ps. (37) 05:12:30.912617 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? peterbilgrav.jo. (33) 05:12:30.913366 IP 193.235.141.239.32768 > 666.42.7.11.53: 14 NS? phoyer.net.lb. (31) 05:12:30.913975 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? phoejager.com.ps. (34) 05:12:30.918513 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? pmk.eg. (24) 05:12:30.919327 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? pmk.ps. (24) 05:12:30.919728 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? pmvinduespolering.com.al. (42) 05:12:30.920403 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? pmvinduespolering.lb. (38) 05:12:30.921196 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? prazsky-krysarik.ps. (37) 05:12:30.924348 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? privatrengoring.com.al. (40) 05:12:30.925556 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? privatrengoring.sz. (36) 05:12:30.927278 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? proces-manager.sz. (35) 05:12:30.928604 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? ramentobiiru.lr. (33) 05:12:30.931413 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? ramentobiiru.org.al. (37) 05:12:30.931977 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? randersbutikker.al. (36) 05:12:30.932049 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? redwheels.ps. (30) 05:12:30.932400 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? redwheels.xn--pgbs0dh. (39) 05:12:30.932625 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? randersbutikker.lr. (36) 05:12:30.934344 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? redwheels.net.al. (34) 05:12:30.934423 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? restaurantguider.eg. (37) 05:12:30.935494 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? retrofjer.az. (30) 05:12:30.935605 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? restaurant-kolding.lr. (39) 05:12:30.935612 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? restaurant-kolding.net.lb. (43) 05:12:30.935890 IP 193.235.141.125.32768 > 666.42.7.11.53: 14 NS? retrofjer.cu. (30) 05:12:30.936973 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? retrospective.al. (34) 05:12:30.939311 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? rexfelt.net.al. (32) 05:12:30.941402 IP 193.235.141.173.32768 > 666.42.7.11.53: 14 NS? rexfelt.com.lb. (32) 05:12:30.942557 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? rincon.al. (27) 05:12:30.942784 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? rincon.com.al. (31) 05:12:30.942945 IP 193.235.141.90.32768 > 666.42.7.11.53: 14 NS? rincon.eg. (27) 05:12:30.944302 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? s-t-a-r.com.al. (32) 05:12:30.945846 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? salonchristy.tn. (33) 05:12:30.946792 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? sammenkomst.mw. (32) 05:12:30.947019 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? salonchristy.al. (33) 05:12:30.947558 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? scandinavianantiques.al. (41) 05:12:30.948872 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? scandinavianantiques.sz. (41) 05:12:30.949380 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? sammenkomst.net.al. (36) 05:12:30.951069 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? scandinavianantiques.org.al. (45) 05:12:30.951304 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? scansani.lr. (29) 05:12:30.952391 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? scandinavianhospitalitysolutions.lr. (53) 05:12:30.953024 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? se-br.lb. (26) 05:12:30.954721 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? semlershop.net.al. (35) 05:12:30.956497 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? semlershop.az. (31) 05:12:30.956595 IP 193.235.141.182.32768 > 666.42.7.11.53: 14 NS? semlershop.com.al. (35) 05:12:30.956653 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? semlershop.com.cu. (35) 05:12:30.957505 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.lr. (34) 05:12:30.957816 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? semlershop.tz. (31) 05:12:30.958134 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.tz. (34) 05:12:30.959803 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.com.lb. (38) 05:12:30.960044 IP 193.235.141.152.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.lb. (34) 05:12:30.960504 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? skjern-skilte.org.al. (38) 05:12:30.960609 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? smaagaver.net.ps. (34) 05:12:30.963373 IP 193.235.141.114.32768 > 666.42.7.11.53: 14 NS? snakspillet.lr. (32) 05:12:30.964082 IP 193.235.141.147.32768 > 666.42.7.11.53: 14 NS? smsfun.cu. (27) 05:12:30.965011 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? snowlab.net.al. (32) 05:12:30.967171 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? socialdebatten.ps. (35) 05:12:30.967788 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? snowlab.net.ps. (32) 05:12:30.968312 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? spapakker.net.al. (34) 05:12:30.971803 IP 193.235.141.215.32768 > 666.42.7.11.53: 14 NS? starstorm.tz. (30) 05:12:30.971864 IP 193.235.141.235.32768 > 666.42.7.11.53: 14 NS? spillefeltet.com.ps. (37) 05:12:30.972227 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? spillefeltet.lr. (33) 05:12:30.974248 IP 193.235.141.164.32768 > 666.42.7.11.53: 14 NS? stuhrcompagniet.lr. (36) 05:12:30.974497 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? strandparken-beboerforening.al. (48) 05:12:30.974819 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? stuhrcompagniet.sz. (36) 05:12:30.975853 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? sukkertand.net.al. (35) 05:12:30.975943 IP 193.235.141.146.32768 > 666.42.7.11.53: 14 NS? strandparken-beboerforening.xn--mgbayh7gpa. (60) 05:12:30.977050 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? stuhrcompagniet.net.lb. (40) 05:12:30.977354 IP 193.235.141.245.32768 > 666.42.7.11.53: 14 NS? sund-i-psyken.net.lb. (38) 05:12:30.978420 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? sukkertand.mw. (31) 05:12:30.978686 IP 193.235.141.187.32768 > 666.42.7.11.53: 14 NS? sund-rejser.lb. (32) 05:12:30.978793 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? sund-rejser.net.al. (36) 05:12:30.980401 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? sund-i-psyken.tn. (34) 05:12:30.980439 IP 193.235.141.3.32768 > 666.42.7.11.53: 14 NS? svanebogholderen.org.al. (41) 05:12:30.980844 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? sund-rejser.com.lb. (36) 05:12:30.981115 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? svarre-hansen.al. (34) 05:12:30.982654 IP 193.235.141.150.32768 > 666.42.7.11.53: 14 NS? svanebogholderen.lr. (37) 05:12:30.986394 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? svinedrengen.ps. (33) 05:12:30.986823 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? swed-mart.sz. (30) 05:12:30.988072 IP 193.235.141.209.32768 > 666.42.7.11.53: 14 NS? svingteknik.xn--mgbayh7gpa. (44) 05:12:30.989526 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? swed-mart.xn--mgbayh7gpa. (42) 05:12:30.989642 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? symedglaede.al. (32) 05:12:30.989786 IP 193.235.141.11.32768 > 666.42.7.11.53: 14 NS? teamferritslev.tn. (35) 05:12:30.990684 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? symedglaede.org.al. (36) 05:12:30.990823 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? teamjohn.net.al. (33) 05:12:30.993586 IP 193.235.141.238.32768 > 666.42.7.11.53: 14 NS? tilbudsapps.eg. (32) 05:12:30.994202 IP 193.235.141.172.32768 > 666.42.7.11.53: 14 NS? testsommerhus.al. (34) 05:12:30.994430 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? testsommerhus.com.ps. (38) 05:12:30.997887 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? toemrermester-larsgyde.lb. (43) 05:12:30.999061 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? toftevej12.eg. (31) 05:12:31.001566 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? tpfrb.tz. (26) 05:12:31.001864 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? trbeton.org.lb. (32) 05:12:31.002217 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? turo4.az. (26) 05:12:31.004424 IP 193.235.141.194.32768 > 666.42.7.11.53: 14 NS? trbeton.ps. (28) 05:12:31.004887 IP 193.235.141.133.32768 > 666.42.7.11.53: 14 NS? turo4.com.lb. (30) 05:12:31.007499 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? unikboligadministration.sz. (44) 05:12:31.008907 IP 193.235.141.210.32768 > 666.42.7.11.53: 14 NS? vaerum.org.ps. (31) 05:12:31.009252 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? vaerum.xn--pgbs0dh. (36) 05:12:31.009586 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? varebilmagasinet.com.lb. (41) 05:12:31.011616 IP 193.235.141.145.32768 > 666.42.7.11.53: 14 NS? veteranbil-mc.net.al. (38) 05:12:31.014456 IP 193.235.141.126.32768 > 666.42.7.11.53: 14 NS? vikogwok.mw. (29) 05:12:31.015144 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? vinkelagerbo.al. (33) 05:12:31.017745 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? visiblepr.org.lb. (34) 05:12:31.019530 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? xn--brnehavenkastaniehuset-5ic.net.al. (55) 05:12:31.020055 IP 193.235.141.176.32768 > 666.42.7.11.53: 14 NS? xn--brnehavenkastaniehuset-5ic.tz. (51) 05:12:31.020458 IP 193.235.141.212.32768 > 666.42.7.11.53: 14 NS? xn--finddkcenter-bdb.com.al. (45) 05:12:31.021672 IP 193.235.141.244.32768 > 666.42.7.11.53: 14 NS? xn--brnehavenkastaniehuset-5ic.cu. (51) 05:12:31.023179 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? xn--finddkcenter-bdb.eg. (41) 05:12:31.024574 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? xn--lvgreen-byg-ggb.sz. (40) 05:12:31.026630 IP 193.235.141.247.32768 > 666.42.7.11.53: 14 NS? xn--lvgreen-byg-ggb.lr. (40) 05:12:31.026703 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? xn--nrregaardadvokatfirma-qfc.eg. (50) 05:12:31.027543 IP 193.235.141.186.32768 > 666.42.7.11.53: 14 NS? xn--nrregaardadvokatfirma-qfc.tz. (50) 05:12:31.028150 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.eg. (41) 05:12:31.028757 IP 193.235.141.21.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.mw. (41) 05:12:31.028804 IP 193.235.141.213.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.net.ps. (45) 05:12:31.029183 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? xn--sams-skaldyr-yjb.tn. (41) 05:12:31.029912 IP 193.235.141.178.32768 > 666.42.7.11.53: 14 NS? xn--nrregaardadvokatfirma-qfc.org.al. (54) 05:12:31.031014 IP 193.235.141.135.32768 > 666.42.7.11.53: 14 NS? zebra-avisen.az. (33) 05:12:31.032044 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? xn--sbolde-bya.az. (35) 05:12:31.033085 IP 193.235.141.7.32768 > 666.42.7.11.53: 14 NS? xn--sbolde-bya.org.ps. (39) 05:12:31.033111 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? adderehub.net.lb. (34) 05:12:31.034472 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? alkes.lr. (26) 05:12:31.034584 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? alkes.net.al. (30) 05:12:31.034893 IP 193.235.141.153.32768 > 666.42.7.11.53: 14 NS? alkes.org.ps. (30) 05:12:31.035227 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? alkes.xn--mgbayh7gpa. (38) 05:12:31.035462 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? arteepropaganda.com.al. (40) 05:12:31.035638 IP 193.235.141.157.32768 > 666.42.7.11.53: 14 NS? adderehub.lb. (30) 05:12:31.036486 IP 193.235.141.143.32768 > 666.42.7.11.53: 14 NS? alkes.az. (26) 05:12:31.037894 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? assistenteonline.org.al. (41) 05:12:31.038307 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? arteepropaganda.eg. (36) 05:12:31.039532 IP 193.235.141.45.32768 > 666.42.7.11.53: 14 NS? assistenteonline.az. (37) 05:12:31.041160 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? avprolamentos.com.cu. (38) 05:12:31.041287 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? avprolamentos.eg. (34) 05:12:31.044035 IP 193.235.141.240.32768 > 666.42.7.11.53: 14 NS? bardompedro.al. (32) 05:12:31.044238 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? bardompedro.com.cu. (36) 05:12:31.045990 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? bradescompletonline.al. (40) 05:12:31.047418 IP 193.235.141.127.32768 > 666.42.7.11.53: 14 NS? clipcomunicacao.az. (36) 05:12:31.050820 IP 193.235.141.168.32768 > 666.42.7.11.53: 14 NS? criativasoft.cu. (33) 05:12:31.051099 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? criativasoft.jo. (33) 05:12:31.051260 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? clipcomunicacao.tz. (36) 05:12:31.051328 IP 193.235.141.60.32768 > 666.42.7.11.53: 14 NS? clipcomunicacao.xn--pgbs0dh. (45) 05:12:31.054433 IP 193.235.141.19.32768 > 666.42.7.11.53: 14 NS? desciclopedia.az. (34) 05:12:31.055795 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? directschool.org.lb. (37) 05:12:31.056389 IP 193.235.141.177.32768 > 666.42.7.11.53: 14 NS? diocesedejales.jo. (35) 05:12:31.060000 IP 193.235.141.224.32768 > 666.42.7.11.53: 14 NS? dlbc.tz. (25) 05:12:31.060842 IP 193.235.141.195.32768 > 666.42.7.11.53: 14 NS? naturheilen.cu. (32) 05:12:31.062017 IP 193.235.141.162.32768 > 666.42.7.11.53: 14 NS? shopwindowstickers.az. (39) 05:12:31.062612 IP 193.235.141.120.32768 > 666.42.7.11.53: 14 NS? shopwindowstickers.net.al. (43) 05:12:31.064165 IP 193.235.141.17.32768 > 666.42.7.11.53: 14 NS? domfinder.lr. (30) 05:12:31.066182 IP 193.235.141.160.32768 > 666.42.7.11.53: 14 NS? domfinder.com.cu. (34) 05:12:31.066612 IP 193.235.141.170.32768 > 666.42.7.11.53: 14 NS? domfinder.lb. (30) 05:12:31.069057 IP 193.235.141.156.32768 > 666.42.7.11.53: 14 NS? sagrimatel.al. (31) 05:12:31.070182 IP 193.235.141.169.32768 > 666.42.7.11.53: 14 NS? flodqvist.lb. (30) 05:12:31.070854 IP 193.235.141.158.32768 > 666.42.7.11.53: 14 NS? flodqvist.sz. (30) 05:12:31.071638 IP 193.235.141.225.32768 > 666.42.7.11.53: 14 NS? rendaonlinetelexfree.org.al. (45)
On Thu, 2 Nov 2023 at 10:32, Mark Andrews <marka@isc.org> wrote:
You missed the point I was trying to make. While I think that that source is trying to enumerate some part of the namespace. NS queries by themselves don’t indicate an attack. Others would probably see the series of NS queries as a signature of an attack when they are NOT. There needs to be much more than that to make that conclusion.
I might be reading this wrong, but I don't think the point Randy was trying to make was 'NS queries are an attack', 'UDP packets are an attack' or 'IP packets are an attack' . I base this on the list of queries Randy decided to include as relevant to the thesis Randy was trying to make, instead of wholesale warning of IP, UDP or NS queries. -- ++ytti
I might be reading this wrong, but I don't think the point Randy was trying to make was 'NS queries are an attack', 'UDP packets are an attack' or 'IP packets are an attack' . I base this on the list of queries Randy decided to include as relevant to the thesis Randy was trying to make, instead of wholesale warning of IP, UDP or NS queries.
i was warning of an ndrek3 enumeration attack from the source netblock's ip space i am far from an expert in ndrek3 enumeration. but i naïvely assume that most tld rrs are ns so that is what they're after. but, as you say, that is beside the point. randy
On 02/11/2023 05:15, Randy Bush wrote:
ya, right, and at a whole bunch of other cctld servers
from a network called domaincrawler-hosting
It looks like a list based attempt to discover domain names registered in some small ccTLDs. The problem with some of the queries is that a few of the second level subdomains of those ccTLDs have just hundreds of registrations. Not sure if it is an DNSSEC based attack. Unlike the gTLDs, available via the ICANN CZDS, most ccTLDs don't provide access to their zone files. Some of the queries are odd because it seems to be applying lists from Swedish or German language sources to small ccTLDs where the main languages of the countries are not Swedish or German. Some of those domain name strings don't exist in the gTLDs. A few of the examples don't exist in the .SE or .DE ccTLDs either. The ccTLDs become more "unique" when the main language of their country is not English. As a ccTLD's market evolves, registrants will often decide to only register in their ccTLD rather than in .COM or other gTLDs. The percentage of these unique registrations, as opposed to registrations having an equivalent in the gTLDs, can be upwards of 15%. The percentage is also affected by economic conditions in the ccTLD's market and the price of a ccTLD registration compared to a .COM registration. The problems for a list based dns enumeration on these small ccTLDs are that there is a lot of them and they are small. It might be an idea to contact Domaincrawler(.)com and ask what it is doing. Regards...jmcc -- ********************************************************** John McCormac * e-mail: jmcc@hosterstats.com MC2 * web: http://www.hosterstats.com/ 22 Viewmount * Domain Registrations Statistics Waterford * Domnomics - the business of domain names Ireland * https://amzn.to/2OPtEIO IE * Skype: hosterstats.com ********************************************************** -- This email has been checked for viruses by Avast antivirus software. www.avast.com
On Thu, Nov 02, 2023 at 04:09:24PM +1100, Mark Andrews <marka@isc.org> wrote a message of 90 lines which said:
I also see QNAME minimisation in action as the QTYPE is NS. This could just be a open recursive servers using QNAME minimisation. With QNAME minimisation working correctly all parent zones should see is NS queries with the occasional DNSKEY and DS query. Both BIND and Knot use NS queries for QNAME minimisation.
I disagree. NS queries were used in the first RFC about QNAME minimisation (which was experimental) but the current one (which is on the standards track) now recommends A or AAAA queries <https://www.rfc-editor.org/info/rfc9156>, specially section 2.1.
Other query types and/or prefixes do not work as they have undesirable side effects.
Rather the contrary, some broken firewalls in front of authoritative name servers were crashing when using NS queries. Hence the choice of address queries. (Also, it improves privacy since it makes more difficult to see you are doing QNAME minimisation.)
I would not like anyone to take seeing mostly NS queries as any evidence of bad practice.
We agree here.
On 2 Nov 2023, at 20:25, Stephane Bortzmeyer <bortzmeyer@nic.fr> wrote:
On Thu, Nov 02, 2023 at 04:09:24PM +1100, Mark Andrews <marka@isc.org> wrote a message of 90 lines which said:
I also see QNAME minimisation in action as the QTYPE is NS. This could just be a open recursive servers using QNAME minimisation. With QNAME minimisation working correctly all parent zones should see is NS queries with the occasional DNSKEY and DS query. Both BIND and Knot use NS queries for QNAME minimisation.
I disagree. NS queries were used in the first RFC about QNAME minimisation (which was experimental) but the current one (which is on the standards track) now recommends A or AAAA queries <https://www.rfc-editor.org/info/rfc9156>, specially section 2.1.
The QTYPE selection is always a matter of trade offs. NS is still perfectly fine and it is the ONLY type that actually works in a number of scenarios. Additionally the number of servers that don’t respond to NS queries is remarkably small and decreasing. More of an issue is garbage NS RRsets below the zone cut. A queries work well when there is a zone cut at each label. They don’t work well when there isn’t a zone cut. You get back nothing to say that there isn’t a zone cut which leaves you needing to do the discovery on the next query to the zone, and the next query to the zone, etc. This leads to complaints that you aren’t caching A (or whatever type you chose) queries.
Other query types and/or prefixes do not work as they have undesirable side effects.
Rather the contrary, some broken firewalls in front of authoritative name servers were crashing when using NS queries. Hence the choice of address queries. (Also, it improves privacy since it makes more difficult to see you are doing QNAME minimisation.)
Hiding that you are doing QNAME minimisation is a non issue. As for firewalls crashing. The more they crash the sooner they get fixed, it’s been years now.
I would not like anyone to take seeing mostly NS queries as any evidence of bad practice.
We agree here.
-- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: marka@isc.org
participants (6)
-
Amir Herzberg
-
John McCormac
-
Mark Andrews
-
Randy Bush
-
Saku Ytti
-
Stephane Bortzmeyer