Opnsense showing attempts to connect to botnet DGA domains

I have noticed opnsense is blocking outgoing connections from the cubesos machine to “Botnet DGA domains”.

Its a stream of www.[insert random string].com destinations.
HTTPS, generic tcp and even pop3 attempts.

I use the device mainly for discord and some adiministration tasks.
Anything else I a untrusted dispîsable for.

I could not locate the origin as it seemed to affect all cubes (debian 13 xfce template).
I reinstalled the template but the problem persisted.
I did not even have to open app cubes for it to happen and even after killing the 2 preload dispo’s and reboot it persisted.

I flashed a usb stick with the installer on a different machine with the latest image.
Did a fresh install, wiped the original ssd.

Only to find it happening again while I was still cloning and preparing app cubes.
The device was isolated in its own vlan with only internet access.

What do I have to think about, do with this?