All Apps and Add-ons

Splunk UBA malware(DGA) Alerts to much

burakatabay
Path Finder

Hi splunkers,
My problem Splunk UBA Malware DGA Alert (Suspicious Domain Name)
in fact this Suspicious Domains are advertising sites
too much dga in an alarm ex: dga count is > 100
AND ı cant control it every sites , indeed one of them can be dga
How can I fix false positives?
alt text
Also that make requests by iphone but alarm can include my dns servers
Sorry for my bad english 🙂
Have a good day :

0 Karma

lakshman239
Influencer

There are 2 anomalies. It's possible, activities (e.g. browsing) from the phone, visited a number of DGA's and hence Suspicious domain names. What's interesting is the Unusual Geolocation comms. Is it possible, one of the visit to the DGA installed a malware which opens a C2C/backdoor to 197.241.* ip address? You may want to scan your device and check for any unusual apps/programme/external comms.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...