CEF:0|Trellix|MPS|9.0.2.925495|RC|riskware-callback|1|rt=Oct 22 2020 09:15:57 UTC start=Oct 22 2020 09:15:57 UTC end=Oct 22 2020 09:15:57 UTC c6a2=2011::1:67e7:bf08 c6a2Label=Victim IP c6a3=2011::1:3c33:39f1 c6a3Label=Attacker IP request=http://savepop.co.kr/app/download/partner/2/savepop_agent.exe cs1Label=sname cs1=Adware.AppCare.Savepop act=notified dvc=xx.x.x.xxx dvchost=abc.mrl.trellix.com smac=00:20:18:11:01:43 dmac=00:01:6c:a9:2f:27 spt=1072 dpt=80 cn1Label=vlan cn1=0 externalId=771 devicePayloadId=0b623598- 7795-4ca1-a1a1-9f2b02ae880b msg=risk ware detected:57 proto=tcp cs4Label=link cs4=https://abc.mrl.trellix.com/detection/objects?uuid\=0b623598-7795-4ca1- a1a1-9f2b02ae880b cs6Label=channel cs6=GET /app/download/partner/2/savepop_ agent.exe HTTP/1.0::~~Host: savepop.co.kr::~~User-Agent: NSISDL/1.2 (Mozilla)::~~Accept: */*::~~::~~ .
riskware-callback (IPv6) (Network Security)
- Published on Aug 25, 2026
- 1 minute(s) read
Was this article helpful?