CEF:0|Trellix|eMPS|9.0.2.925255|MO|malware-object|4|requestClientApplication=Mozilla/4.0 (compatible; msie 40; NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR 00000000/00000000) cn2Label=sid cn2=33351836 cs5Label=cncHost cs5=xezlifewvupazah.ws cs2Label=anomaly cs2=99329 cn1Label=vlan cn1=0 cs4Label=link cs4=https://abc-123.mrl.trellix.com/emps/eanalysis?e_id\=12&type\=attch rt=Oct 22 2020 07:33:36 UTC proto=tcp externalId=20 msg=51790836-a876-32aa-a2db-e6e0023e0230@tesoro.com fileHash=ebe52c916b26694796abef44b154e58e filePath=......... ............... ............... ............ ......... cs3Label=osinfo cs3=Microsoft Windows7 64-bit 6.1 sp1 17.0114 suser=sample@tesoro.com dvchost=abc-123.mrl.trellix.com duser=samples@tesoro.com cs6Label=channel cs6=POST xezlifewvupazah.ws HTTP/1.1::~~User-Agent: Mozilla/4.0 (compatible; msie 40; NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR 00000000/00000000)::~~::~~ cn3Label=cncPort cn3=80 dvc=xx.x.x.xxx requestMethod=POST act=blocked cs1Label=sname cs1=fe_ml_heuristic devicePayloadId=68c16bee-87d4-44e4-a098-ee58a55aeb44 fileType=exe sproc=Windows Explorer fsize=327680 fname=......... ............... ............... ............ ......... flexString1Label=sha256sum flexString1=83920de959a29be45ff40a3f513f7ec94ad21433e009a3f9e36dea44a8d42b45 start=Oct 22 2020 07:30:24 UTC flexString2Label=subject flexString2=mal sample :: original sourceDnsDoma 07:33:37.885109 IP xx.x.x.xxx > xx.x.x.xxx: ip-proto-17 E..#.=..@..m
malware-object (Email Security)
- Published on Aug 25, 2026
- 1 minute(s) read
Was this article helpful?