The SIEM product I use generates alarms based on a connection from a Cloudflare IP address which uses a Malicious SSL certificate. The certificate is linked to Dyre malware and uses a certificate from November 2015 so has expired.
Has anyone experienced something similar to this or suggest a possible reason for this?
Thank you for any help or thoughts!