Skip to main content
kushh8
New Member
July 23, 2023
Question

FortiGate newly observed domains - control-xxxxxxxxxxxxxxxx.com

  • July 23, 2023
  • 1 reply
  • 3767 views

Hello, I've been receiving event detections in the category 'Newly Observed Domain'. They are pretty common but recently I noticed quite a few of them with the template type 'control-xxxxxxxxxxxxxxxx[.]com', where the 'x' represents a string random characters. These are usually preceded by a vpn connection to Mullvad vpn.Has anyone come across this before? Appears suspicious but I'm unable to make any connections.

1 reply

srajeswaran
Staff
Staff
July 23, 2023

As the alert name states, these are generated when the Fortigate/Fortiguard observes a URL that is not their database. You can find more details about this in below article.
Can you check the source IP/user for these logs, are there any common points? May be someone is testing some application or  their pc is infected.


https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-category/ta-p/250697

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!