Server is sending out dns requests to suspicious sites

Latest response

Server is sending out dns requests to some suspicious sites but unable to find the process generating the request.
Methods to find out the offending process was not successful.
E.g. - Tried checking the tcpdump output.
By the time I check the port number from the output with the netstat
or lsof command, can't see any process using the port.
Any other ideas?

Responses