Signature
alert tcp any any <> 213.32.29.150 any ( msg: Crypto Miner: [ 213.32.29.150 ]" ; rev:1; sid:4000471; )"
MITRE ATT&CK Technique
T1496: Resource Hijacking
Recommendations/Investigative actions
It is recommended to block all communication to this IP address and identify the internal device(s) communicating with this IP address. Investigate the nature of the traffic and the software or processes responsible for it.
Relations to other alerts