Question
FortiGate newly observed domains - control-xxxxxxxxxxxxxxxx.com
Hello, I've been receiving event detections in the category 'Newly Observed Domain'. They are pretty common but recently I noticed quite a few of them with the template type 'control-xxxxxxxxxxxxxxxx[.]com', where the 'x' represents a string random characters. These are usually preceded by a vpn connection to Mullvad vpn.Has anyone come across this before? Appears suspicious but I'm unable to make any connections.
