riskware-object (Email Security)

Prev Next
CEF:0|Trellix|eMPS|9.0.2.925255|RO|riskware-object|1|rt=Oct 22 2020 10:09:29
UTC start=Oct 22 2020 10:07:11 UTC end=Oct 22 2020 10:09:29 UTC
fname=BottCom_riskware1.exe fileType=exe cs1Label=sname cs1=Adware.FileTour
act=blocked dvc=10.5.6.115 dvchost=abc-123.mrl.trellix.com
fileHash=23780117a00b9b3526c3a0a3ea7c590f fsize=1887256 cn1Label=vlan cn1=0
externalId=29 devicePayloadId=8c145d59-3b5e-4bab-b628-f88476ba092c msg=risk
ware detected:2 cs3Label=osinfo cs3=Microsoft WindowsXP 32-bit 5.1 sp3
17.0114 cs4Label=link cs4=https://abc-
123.mrl.trellix.com/detection/objects?uuid\=8c145d59-3b5e-4bab-b628-
f88476ba092c cs6Label=channel cs6=GET /php/track1.php HTTP/1.0::~~Host:
soft.freemusicdownloads.world::~~User-Agent: InnoTools_Downloader::~~::~~
flexString1Label=sha256sum
flexString1=c78be5b7b2bcb2c69ae2c1d161a2f89710638f852ddabbce0f8f675272d559e4
suser=sample@tesoro.com duser=samples@tesoro.com sourceDnsDomain=tesoro.com
applicationProtocol=smtp .