Hi Benoit,

On Thu, Feb 26, 2009 at 11:44, Benoit Panizzon <benoit.panizzon@imp.ch> wrote:
In the last few days I observer strange virus DNS behaviour... 

Its a double-fast-flux network:
http://en.wikipedia.org/wiki/Fast_flux#Single-flux_and_double-flux
http://spamtrackers.eu/wiki/index.php?title=Fast-flux#How_to_shut-down_a_fast-flux_domain
http://dnsbl.abuse.ch/fastfluxtracker.php

Jeroens answer is probably the easiest to implement.

-Aarno
--
Aarno Aukia
ETH Zurich / Atrila GmbH
+41764000464