ET INFO TLS Handshake Failure ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET POLICY External IP Lookup ip-api.com ET HUNTING Telegram API Domain in DNS Lookup
ET COINMINER CoinMiner Domain in DNS Lookup (pool .hashvault .pro) ET INFO Observed DNS Query to Cryptocurrency Mining Pool Domain (xmr .2miners .com) ET MALWARE Win32/Pripyat Activity (POST)