This alert is triggered when a high volume of requests 100 in 1 second resembling brute-force password cracking attempts are sent to a MySQL server on port 3306. This behavior is indicative of an attacker attempting to guess MySQL account passwords rapidly.
This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .ru (Russia).
This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .cc, which is registered in the Cocos Islands, a group of islands in the Indian Ocean belonging to Australia. This Domain extension is often used as an alternative to the more common extensions such as .com or . net because it is easy to remember and easy to find.
This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .zip. This domain ending is sometimes linked to suspicious or malicious activities.
This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .xyz. This domain ending is sometimes linked to suspicious or malicious activities.