ESET Protection Suite

2023-09-13 by Petr Špaček (@pspacek)

Everybody loves a big DNS query!

Various modules of ESET protection suite (Antispam, Parental Controls, LiveGrid) perform odd DNS lookups to subdomains of e5.sk domain.

Example:

TXT? oa5jhh3yxkgu5kpwgnjmgk54pubqeaqbaeaq.a.e.e5.sk.
TXT? wzxh7gqaszmunhqg3g5ouiiuwebqeaqbaeaq.a.e.e5.sk.
TXT? xegjkvpuklfebhejqeve4mltsmbqeaqbaeaq.a.e.e5.sk.
TXT? vscxkxbn55aelaru6a6y3dxznebqeaqbaeaq.a.e.e5.sk.
TXT? dc5wtaihc6luvphgub6laccokebqeaqbaeaq.a.e.e5.sk.

Documentation