To request access this dataset you will need to login with an IMPACT account. Accounts are free. If you don't have one please register.
GT Malware Passive DNS Data 2011-2013
This dataset contains a historical archive of passive DNS data produced by the Georgia Tech Information Security Center??s malware analysis system for calendar years 2011, 2012 and 2013. It was produced by executing suspect Windows executables in a sterile, isolated environment, with limited access to the Internet, for a short period of time. Each sample??s use of the DNS was recorded and used to create a 4-tuple comprising the executable's MD5 hash, the date in which the executable was processed, the qname (domain name) of the DNS query, and (if the query was of type A) a resolution IP address for the domain name.
The dataset consists of multiple CSV files, with one CSV file per month. The contents of each file are sorted by process date, executable MD5, qname, and resolution IP address. As mentioned previously, for a given qname at most one resolution IP address is provided, even if the query resulted in a response record set that contains multiple resolution addresses.
2011, georgia, tech, dns, malware, 2013, passive, gt, historical, historical gt malware passive dns data 2011-2013, 433, georgia tech, resolution, qname, query, executable, domain, csv, file, multiple, dataset, md5, produced, processed, center, archive, suspect, windows, comprising, period, sample, create, limited, environment, response, type, short, consists, time, executing, executables, sorted, sterile, month, files, hash, access, system, 2012, isolated, contents, tuple, security, dns data, mentioned, calendar, process, analysis