You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
WTF Behavior Description: Samsung MobileWips (presumably a Wireless Intrusion Prevention System) is a default system app on certain Android OS versions. It has been observed making DNS requests to google.com.onion, which will trigger network/DNS-related alerts, such as the Sigma rule Query Tor Onion Address. This domain does not resolve to an IP address, and is not accessible via Tor. It appears to have been added as some sort of DNS check by an Android developer with poor taste!
Thanks @mttaggart! Would you mind correcting my Twitter handle when you get a chance? There should be an "i" at the end not a "y". I appreciate all you do!
https://isc.sans.edu/forums/Strange+Googleish+domain+name+lookups+after+update+to+Android+10/2666/
https://www.reddit.com/r/samsunggalaxy/comments/eq0qu5/weird_googleish_domains_from_samsung_galaxy_s10/
https://pastebin.com/bNteJBFH
The text was updated successfully, but these errors were encountered: