Look closer at your log entry and the information, why it is only detected, is directly included!
In the field "Description" is the following information:
DNS response was replaced with a DNS trap bogus IP
Also there is sk74060 mentioned, where everything is explained regarding the DNS trap feature.
Also keep in mind that by default DNS traffic is always handled in background mode (since R75.47 / R76) as a hold might cause DNS timeouts. So there might be also DNS detects because classification is not completed yet.
This behavior is documented in sk92224