Resolved! DNS sinkhole not blocking malware
PC does DNS query, which gets inspected and is not sinkholed. PC then sends traffic to resolved address which gets inspected and blocked as malware. This is the pattern i am seeing right now and this is not for a single domain. I am not saying sinkhole is not working, it is working but not for all destinations. Below is the example of both sink...




