Hello all,
A few weeks ago, a suspicious communication towards the domain “4s.pm” was identified by Anti-Virus blade and DNS trap was successfully enforced.
Since then, what we notice and we can not explain is the fact that if we search for “DNS Trap” all the results refer as destination “4s.pm” (screenshot 1). This is weird and most possibly false because if we randomly open one of these logs (Screenshot 2), in the forensics section the actual domain is referred and it is not “4s.pm”.
Can somebody help us understand the behavior?