2023-01-17 11:19 AM - edited 2023-01-17 12:14 PM
Is it possible to find out what this triggers on?
Every Day I learn how more about how much I don't know. As soon as I submitted this post I came across this Blog post from July 2017.
It is a very good read. It has the following information in it that I think answers my question:
"payment domain (key.dga.tld pattern) as 'cerber ransomware' and the UDP spray as 'cerber beacon' in the <Indicators of Compromise> meta field."