Malware Hit Found (Endpoint Security)

Prev Next
CEF:0|trellix|hx|9.9.0|Malware Hit Found|Malware Hit Found|10|rt=Feb 05 2019
17:00:36 UTC dvchost=trellix-01cb28 categoryDeviceGroup=/IDS
categoryDeviceType=Malware Protection categoryObject=/Host cs1Label=Host
Agent Cert Hash cs1=HawW2jJc9O6bDMZDqxo30s dst=10.61.155.119 dmac=00-50-56-
01-cb-23 dhost=WIN2feff6846b7d dntdom=WORKGROUP deviceCustomDate1Label=Agent
Last Audit deviceCustomDate1=Feb 05 2019 16:55:51 UTC cs2Label=Trellix Agent
Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS
cs6=Windows 7 Enterprise 7601 Service Pack 1 externalId=1 start=Feb 05 2019
17:00:35 UTC categoryOutcome=/Success categorySignificance=/Compromise
categoryBehavior=/Found cs7Label=Resolution cs7=QUARANTINED cs8Label=Alert
Types cs8=malware cs12Label=Malware Category cs12=file-event act=Detection
MAL Hit msg=Host WIN2feff6846b7d Malware alert
categoryTupleDescription=Malware Protection found a compromise indication.
cs4Label=Process Name cs4=C:\\Python27\\python.exe cs9Label=MD5
cs9=06f391ea3f127ffc3bba3d56f374077f cs10Label=SHA1
cs10=2a85b25f583127a3903bbcd1c7187bcdb58b5c5b cs11Label=Malware Signature
cs11=Generic.mg.06f391ea3f127ffc categoryTechnique=Malware cs13Label=Malware
Engine cs13=MG