We run a pair of ASA's with a Botnet license. Recently (like this week) I have been noticing an increase of dynamic filter alerts for IP 65.55.239.168. This is a registered Microsoft IP, which makes me suspect that someone is running possibly a DNS...