Sign-In From Malware Infected IP (821b4dc3-1295-41e7-b157-39ab212dd6bd)
Indicates sign-ins from IP addresses infected with malware that is known to actively communicate with a bot server.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Sign-In From Malware Infected IP (821b4dc3-1295-41e7-b157-39ab212dd6bd) | Sigma-Rules | Proxy - T1090 (731f4f55-b6d0-41d1-a7a9-072a66389aea) | Attack Pattern | 1 |