ET INFO External IP Address Lookup Domain in DNS Lookup (reallyfreegeoip .org)
ET HUNTING Telegram API Domain in DNS Lookup
ET POLICY External IP Lookup - checkip.dyndns.org
ET INFO 404/Snake/Matiex Keylogger Style External IP Check
ET INFO External IP Lookup Domain in DNS Query (checkip .dyndns .org)
ET INFO TLS Handshake Failure
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
ET INFO External IP Lookup Service Domain (reallyfreegeoip .org) in TLS SNI