malware-object (Network Security)

Prev Next
CEF:0|Trellix|MPS|9.0.2.924861|MO|malware-object|4|rt=Oct 16 2020 14:41:48 UTC src=192.168.2.62 cn3Label=cncPort
cn3=53 dpt=80 dst=xxx.xxx.x.xxx fileHash=0d043e3acbc3af58970d3365b6f91d29 filePath=xxx.xxx.x.xxx/images/miscexes/
0d043e3acbc3af58970d3365b6f91d29.exe cs5Label=cncHost cs5=wa3d.no-ip.biz dvchost=abc.mrl.trellix.com
cs3Label=osinfo cs3=Microsoft WindowsXP 32-bit 5.1 sp3 17.0114 proto=udp spt=3926 dvc=xx.x.x.xxx smac=00:50:8b:
08:b8:f6 cn1Label=vlan cn1=0 externalId=32 cs4Label=link cs4=https://abc.mrl.trellix.com/event_stream/
events_for_bot?ma_id\=32 act=notified dmac=00:02:b3:a1:87:14 cs2Label=anomaly cs2=98304 cs1Label=sname
cs1=Win.Trojan.Bifrose-194 devicePayloadId=d7563e4c-b4b4-433c-92e9-8591a225b1a5 fileType=exe sproc=Windows
Explorer fsize=89282 fname=0d043e3acbc3af58970d3365b6f91d29.exe flexString1Label=sha256sum
flexString1=9a8724dfb4ae1f044a28be30ff3885b7558d1ae00664308ecb11f7164a7a3ddf start=Oct 16 2020 14:36:18 UTC .