CEF:0|Trellix|CMS|9.0.0.916210|IM|infection-match|1|requestClientApplication=Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) cn2Label=sid cn2=600145 cs5Label=cncHost cs5=xxx.xxx.xxx.xxx spt=1158 smac=92:73:75:00:00:35 cn1Label=vlan cn1=0 cs4Label=link cs4=https://abc.mrl.trellix.com/event_stream/ events_for_bot?ev_id\=70183 rt=Jun 28 2020 09:02:19 UTC shost=119-168-188-108.rev.home.ne.jp proto=tcp dst=153.187.245.174 externalId=70183 dmac=00:19:d1:fd:a2:52 dvchost=xxxx cs6Label=channel cs6=GET /0014.exe HTTP/1.1::~~Accept: */*::~~Accept-Encoding: gzip, deflate::~~User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)::~~Host: b.s102-cnzz.com::~~Connection: Keep-Alive::~~::~~ src=xxx.xxx.xxx.xxx cn3Label=cncPort cn3=80 dpt=80 dvc=xx.x.x.xxx requestMethod=GET act=notified cs1Label=sname cs1=Local.Infection devicePayloadId=9b380d2f-469a-4874-8327-a314205e5d0c
infection-match (Network Security on Central Management)
- Published on Aug 25, 2026
- 1 minute(s) read
Was this article helpful?