This alert looks for the presence of the MrbMiner malware by checking for an account in sys.sql_logins (in the master database).
In case a system with this account is found, full network audits are recommended.
More info:
https://www.zdnet.com/article/new-mrbminer-malware-has-infected-thousands-of-mssql-databases/