All Apps and Add-ons

Splunk UBA malware(DGA) Alerts to much

burakatabay
Path Finder

Hi splunkers,
My problem Splunk UBA Malware DGA Alert (Suspicious Domain Name)
in fact this Suspicious Domains are advertising sites
too much dga in an alarm ex: dga count is > 100
AND ı cant control it every sites , indeed one of them can be dga
How can I fix false positives?
alt text
Also that make requests by iphone but alarm can include my dns servers
Sorry for my bad english 🙂
Have a good day :

0 Karma

lakshman239
Influencer

There are 2 anomalies. It's possible, activities (e.g. browsing) from the phone, visited a number of DGA's and hence Suspicious domain names. What's interesting is the Unusual Geolocation comms. Is it possible, one of the visit to the DGA installed a malware which opens a C2C/backdoor to 197.241.* ip address? You may want to scan your device and check for any unusual apps/programme/external comms.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...