This document summarizes research conducted by OpenDNS on catching malware using DNS and IP data. It describes how OpenDNS analyzed DNS records to track fast flux botnets, crimeware command and control infrastructure, and phishing domains. Visualization techniques were used to create graphs of the relationships between domains and IP addresses over time. This research enabled OpenDNS to detect and block new strains of malware.