Sept. 2, 2022, 5:04 p.m. | /u/callme_e

cybersecurity www.reddit.com

Hello, I've been seeing a reoccurrence in our SIEM daily reports about random workstation's Edge browser trying to communicate to a Russian IP shown below. It shows it blocked and closed the process, but I'm concerned if this is some IOC or a risk.

I'm also a bit new to security so any tips are appreciated!

Reason: Communicating to a suspicious IP address Hash (MD5): c3c1a31b7a233efd3683d9bcbd0ceb60
 

Process Name: msedge.exe Image File Name: C:\Program Files
(x86)\Microsoft\Edge\Application\msedge.exe

Remote Address: 213.180.204.90

Remote …

cybersecurity process russian siem

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Cybersecurity Consultant- Governance, Risk, and Compliance team

@ EY | Tel Aviv, IL, 6706703

Professional Services Consultant

@ Zscaler | Escazú, Costa Rica

IT Security Analyst

@ Briggs & Stratton | Wauwatosa, WI, US, 53222

Cloud DevSecOps Engineer - Team Lead

@ Motorola Solutions | Krakow, Poland