logo

DGA botnet domains: on false alarms in detection

ID: f3f65fec-cf90-5be8-8c04-02e9b9ce34ae

STIX ID: report--f3f65fec-cf90-5be8-8c04-02e9b9ce34ae

Feed Name: CERT Polska

Date Published: 2015-04-17

Date Updated: 2026-04-19

Author: CERT Polska

...
...

This article reviews multiple benign causes of seemingly random or DGA-like domain lookups—covering McAfee GTI File Reputation queries, DNS blacklist/geolocation checks (Spamhaus DBL, countries.nerd.dk), internationalized domain names encoded with Punycode (xn--), Chrome/Chromium NXDomain hijack tests, Google metric and pack.google.com requests, and CDN hostnames—and explains how these patterns can be misclassified as botnet activity, offering guidance to reduce false positives while reserving malicious examples for a subsequent post.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.