Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kushh8
New Contributor

FortiGate newly observed domains - control-xxxxxxxxxxxxxxxx.com

Hello, I've been receiving event detections in the category 'Newly Observed Domain'. They are pretty common but recently I noticed quite a few of them with the template type 'control-xxxxxxxxxxxxxxxx[.]com', where the 'x' represents a string random characters. These are usually preceded by a vpn connection to Mullvad vpn.Has anyone come across this before? Appears suspicious but I'm unable to make any connections.

192.168.0.1 192.168.l.l
1 REPLY 1
srajeswaran
Staff
Staff

As the alert name states, these are generated when the Fortigate/Fortiguard observes a URL that is not their database. You can find more details about this in below article.
Can you check the source IP/user for these logs, are there any common points? May be someone is testing some application or  their pc is infected.


https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-cate...

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Labels
Top Kudoed Authors