malware-object (Email Security)

Prev Next
CEF:0|Trellix|eMPS|9.0.2.925255|MO|malware-object|4|requestClientApplication=Mozilla/4.0 (compatible; msie 40;
NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR 00000000/00000000) cn2Label=sid cn2=33351836
cs5Label=cncHost cs5=xezlifewvupazah.ws cs2Label=anomaly cs2=99329 cn1Label=vlan cn1=0 cs4Label=link
cs4=https://abc-123.mrl.trellix.com/emps/eanalysis?e_id\=12&type\=attch rt=Oct 22 2020 07:33:36 UTC proto=tcp
externalId=20 msg=51790836-a876-32aa-a2db-e6e0023e0230@tesoro.com fileHash=ebe52c916b26694796abef44b154e58e
filePath=......... ............... ............... ............ ......... cs3Label=osinfo cs3=Microsoft Windows7
64-bit 6.1 sp1 17.0114 suser=sample@tesoro.com dvchost=abc-123.mrl.trellix.com duser=samples@tesoro.com
cs6Label=channel cs6=POST xezlifewvupazah.ws HTTP/1.1::~~User-Agent: Mozilla/4.0 (compatible; msie 40;
NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR 00000000/00000000)::~~::~~ cn3Label=cncPort
cn3=80 dvc=xx.x.x.xxx requestMethod=POST act=blocked cs1Label=sname cs1=fe_ml_heuristic
devicePayloadId=68c16bee-87d4-44e4-a098-ee58a55aeb44 fileType=exe sproc=Windows Explorer fsize=327680
fname=......... ............... ............... ............ ......... flexString1Label=sha256sum
flexString1=83920de959a29be45ff40a3f513f7ec94ad21433e009a3f9e36dea44a8d42b45 start=Oct 22 2020 07:30:24 UTC
flexString2Label=subject flexString2=mal sample :: original sourceDnsDoma 07:33:37.885109 IP xx.x.x.xxx >
xx.x.x.xxx: ip-proto-17 E..#.=..@..m