Hello, I've been receiving event detections in the category 'Newly Observed Domain'. They are pretty common but recently I noticed quite a few of them with the template type 'control-xxxxxxxxxxxxxxxx[.]com', where the 'x' represents a string random characters. These are usually preceded by a vpn connection to Mullvad vpn.Has anyone come across this before? Appears suspicious but I'm unable to make any connections.
As the alert name states, these are generated when the Fortigate/Fortiguard observes a URL that is not their database. You can find more details about this in below article.
Can you check the source IP/user for these logs, are there any common points? May be someone is testing some application or their pc is infected.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-cate...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.