Here we come up with quite some answers: http://totalhash.com/network/dnsrr:*127.0.0.2*%20or%20ip:127.0.0.2
What is the common denominator here? Detected a Dynamic DNS URL!
Spam mail bots? → https://www.mywot.com/en/scorecard/quowesuqbbb.mooo.com
Botnet C&C? Seen with worms like W32/Parite! They should fix their stuff!
Here is the final word and IDS alert: http://urlquery.net/report.php?id=9210970 IDS alert for ET TROJAN Known Sinkhole Response Header
Also read here: http://seclists.org/snort/2013/q4/665
and also study this paper here: http://www.sans.org/reading-room/whitepapers/dns/dns-sinkhole-33523?show=dns-sinkhole-33523&cat=dns
article author Guy Bruneau advisor Rick Wanner

polonus