ACE Alert (Email Security — Cloud Edition)

Prev Next

Note

Every ACE alert generates a separate CEF notification.

CEF:0|Trellix|ETP|3.0|etp|ace alert|10|rt=Nov 07 2016 23:27:17 UTC
suser=yser@abc.com duser=usera@xyz.pqr.com fname=test.zip
fileHash=5b61d32c94ca81d4f28241ca29aca9b9 destinationDnsDomain=xyz.pqr.com
externalId=9999999 cs1Label=sname cs1=Malware.archive cs3Label=Subject
cs3=Arc Sight Test CEF cs4Label=Link
cs4=https://etp.trellixcloud.com/alert/9999999/ cs5Label=Client cs5=AAAA
cs6Label=ATI Name Type Level cs6=Exploit.DTI.CVE-2008-2992\|Exploit\|Medium
flexString1Label=ATI Threat Attribution flexString1=While many well-known
exploit kits used to weaponize the CVE-2008-2992 exploit, the popularity of
this exploit has drastically dropped overtime due to Adobe Reader’s sandbox
mechanism. No APT actors have been found to actively leverage this exploit in
current cyber operations. Metasploit, however, still has a module targeting
CVE-2008-2992 vulnerability. As this exploit is old, the latest versions of
Adobe application are already patched against this attack. It is strongly
advised to update Adobe Acrobat and Reader to versions 8.1.2 and above as
soon as possible.