Unusual DNS queeries

DaveITBS 1 Reputation point
2020-08-26T15:29:30.457+00:00

Does anyone have any idea why a DNS server would generate unusual dns queries to what appears to be a malicious C&C site? AV scans don't seem to find root cause of any kind.

Windows for business | Windows Server | User experience | Other
{count} votes

3 answers

Sort by: Most helpful
  1. Anonymous
    2020-08-26T15:31:18.877+00:00

    What tools are being used to monitor?

    0 comments No comments

  2. Thameur-BOURBITA 36,261 Reputation points Moderator
    2020-08-26T22:45:48.007+00:00

    Hi,

    You can launch network capture to check and get more details about the source of those queries

    Don't forget to mark this reply as answer if it help you to fix your issue

    0 comments No comments

  3. Anonymous
    2020-08-27T10:25:35.857+00:00

    Hi,

    Thanks for posting in Q&A platform.

    Regarding of your issue, I would like to suggest that you could download the Network Monitor to collect network tracs in order to identify the source of DNS request.

    Please download the “Network Monitor” as below link:
    https://www.microsoft.com/en-sg/download/details.aspx?id=4865

    And here is an related thread for your reference:
    https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/DNS-trap-bogus-IP/td-p/16753
    Please Note: Since the websites are not hosted by Microsoft, the links may change without notice. Microsoft does not guarantee the accuracy of this information.

    Hope my answer will help you!

    ---Please Accept as answer if the reply is helpful---

    Best Regards,
    Sunny

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.