CEF:0|Trellix|CMS|9.0.0.916210|RC|riskware-callback|1|rt=Jun 29 2020 07:49:43 UTC end=Jun 29 2020 07:49:43 UTC src=xx.x.x.xx dst=xxx.xx.xxx.x request=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3- 8a58-80c16e6f498c/12932238/config cs1Label=sname cs1=Adware.MultiPlug act=notified dvc=xx.x.x.xx dvchost=abc.xyz.trellix.com smac=00:20:18:11:01:43 dmac=00:01:6c:a9:2f:27 spt=1072 dpt=80 cn1Label=vlan cn1=0 externalId=380 devicePayloadId=36e8bce0-1f70-44bf-ae14-90c7946422d7 msg=risk ware detected:29 proto=tcp cs4Label=link cs4=https://abc.xyz.trellix.com/detection/objects?uuid\=36e8bce0-1f70-44bfae14- 90c7946422d7 cs6Label=channel cs6=GET /installer/ad0d8641-dff0-11e3- 8a58-80c16e6f498c/12932238/config HTTP/1.1::~~Accept-Language: en-XX::~~User- Agent: DownloadMR/1.2.4+ (MSIE 8.0; Windows NT 5.1 SP3; DB\=ie; 9bf59659- 7f5b-02eb-8c69-ce6a8ca6b231; m\=wXuH; u\=admin; aurora)::~~Host: 49939.northstar.api.socdn.com::~~Connection: Keep-Alive::~~::~~
riskware-callback (Network Security on Central Management)
- Published on Aug 25, 2026
- 1 minute(s) read
Was this article helpful?