All Apps and Add-ons

Splunk UBA malware(DGA) Alerts to much

burakatabay
Path Finder

Hi splunkers,
My problem Splunk UBA Malware DGA Alert (Suspicious Domain Name)
in fact this Suspicious Domains are advertising sites
too much dga in an alarm ex: dga count is > 100
AND ı cant control it every sites , indeed one of them can be dga
How can I fix false positives?
alt text
Also that make requests by iphone but alarm can include my dns servers
Sorry for my bad english 🙂
Have a good day :

0 Karma

lakshman239
Influencer

There are 2 anomalies. It's possible, activities (e.g. browsing) from the phone, visited a number of DGA's and hence Suspicious domain names. What's interesting is the Unusual Geolocation comms. Is it possible, one of the visit to the DGA installed a malware which opens a C2C/backdoor to 197.241.* ip address? You may want to scan your device and check for any unusual apps/programme/external comms.

0 Karma
Get Updates on the Splunk Community!

New Case Study: How LSU’s Student-Powered SOCs and Splunk Are Shaping the Future of ...

Louisiana State University (LSU) is shaping the next generation of cybersecurity professionals through its ...

Splunk and Fraud

Join us on November 13 at 11 am PT / 2 pm ET!Join us for an insightful webinar where we delve into the ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...