- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiGate newly observed domains - control-xxxxxxxxxxxxxxxx.com
Hello, I've been receiving event detections in the category 'Newly Observed Domain'. They are pretty common but recently I noticed quite a few of them with the template type 'control-xxxxxxxxxxxxxxxx[.]com', where the 'x' represents a string random characters. These are usually preceded by a vpn connection to Mullvad vpn.Has anyone come across this before? Appears suspicious but I'm unable to make any connections.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As the alert name states, these are generated when the Fortigate/Fortiguard observes a URL that is not their database. You can find more details about this in below article.
Can you check the source IP/user for these logs, are there any common points? May be someone is testing some application or their pc is infected.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-cate...
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
