Connection with IP marked as malicious by my EDR
In our environment we had alerts coming from two different devices, but both originated from Firefox.
The alarm refers to an outbound connection to the IP 34.107.243.93 marked as a malicious reputation by my EDR. What caught our attention was that on one of the machines the alert happened shortly after installation, the user had not yet accessed any site.
In our environment we had alerts coming from two different devices, but both originated from Firefox.
The alarm refers to an outbound connection to the IP 34.107.243.93 marked as a malicious reputation by my EDR. What caught our attention was that on one of the machines the alert happened shortly after installation, the user had not yet accessed any site.