Malware Hit Found (Endpoint Security)

Prev Next
CEF:0|trellix|hx|9.9.0|Malware Hit Found|Malware Hit Found|10|rt=Feb 05 2019 17:00:36 UTC dvchost=trellix-01cb28
categoryDeviceGroup=/IDS categoryDeviceType=Malware Protection categoryObject=/Host cs1Label=Host Agent Cert
Hash cs1=<agent host name hash> dst=<agent host IP address> dmac=<agent host MAC address> dhost=<agent host
name> dntdom=<agent host Windows domain> deviceCustomDate1Label=Agent Last Audit deviceCustomDate1=Feb 05 2019
16:55:51 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS
cs6=Windows 7 Enterprise 7601 Service Pack 1 externalId=1 start=Feb 05 2019 17:00:35 UTC categoryOutcome=/
Success categorySignificance=/Compromise categoryBehavior=/Found cs7Label=Resolution cs7=QUARANTINED
cs8Label=Alert Types cs8=malware cs12Label=Malware Category cs12=file-event act=Detection MAL Hit msg=Host
WIN2feff6846b7d Malware alert categoryTupleDescription=Malware Protection found a compromise indication.
cs4Label=Process Name cs4=C:\\Python27\\python.exe cs9Label=MD5 cs9=06f391ea3f127ffc3bba3d56f374077f
cs10Label=SHA1 cs10=2a85b25f583127a3903bbcd1c7187bcdb58b5c5b cs11Label=Malware Signature cs11=Generic.mg.
06f391ea3f127ffc categoryTechnique=Malware cs13Label=Malware Engine cs13=MG