Sample LEEF notifications per event type

Prev Next

Sample LEEF notifications are shown for various event types. The definitions for each of the <extension> field keys are provided in LEEF extension field key=value pair definitions.

Note

The product names in notifications are ‘MPS’ (for Network Security), ‘eMPS’ (for Email Security — Server Edition) ‘fMPS’ (for File Protect), ‘MAS’ (for Malware Analysis), and ‘CMS’ (for Central Management).

domain-match (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916248|domain-match|sev=1^sname=Trojan.Win32.Dogrobot.gen.E^shost=xxx-xxx-xxxxxx.
rev.home.ne.jp^srcMAC=92:73:75:00:00:35^proto=udp^srcPort=1025^vlan=0^dstMAC=00:19:d1:fd:a2:52^dvc=xx.x.x.x
xx^action=notified^dvchost=abc.mrl.trellix.com^cncHost=the.microgood.net^externalId=226^devTime=Jun 29 2020
08:35:55 UTC^sid=89017273^cncPort=53^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=226^filePath=the.microgood.net^src=xxx.xxx.xxx.xxx^uuid=1a250f4b-bd82-4828-9752-4e2ffff8bdf2^

domain-match (Network Security on Central Management)

LEEF:1.0|Trellix|MPS|9.0.2.924861|domainmatch|
sev=1^sname=Trojan.Ramnit.SNK.DNS^dvchost=abc.mrl.trellix.com^srcMAC=6a:c0:02:9a:9b:7d^proto=udp^srcPort=
1070^vlan=0^dstMAC=00:50:56:e5:3f:c5^dvc=xx.x.x.xxx^action=notified^cncHost=fgetcareer.
com^externalId=85^devTime=Oct 16 2020 14:36:16
UTC^sid=80461038^cncPort=53^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=85^filePath=fget-career.com^src=xxx.xxx.xxx.xxx^start=Oct 16 2020 14:36:16 UTC^uuid=95846ab0-a464-43e1-
a89f-9a0e51f3a4b1^ .

infection-match (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|infectionmatch|
sev=1^dstPort=80^sname=Worm.Ramnit^dvchost=abc.mrl.trellix.com^srcMAC=6a:c0:02:9a:9b:7d^proto=tcp^srcPort
=1058^dst=xxx.xxx.xxx.xxx^vlan=0^dstMAC=00:50:56:e5:3f:c5^request=hxxp://yy8311.com/?/goods_list/14_25_
0^dvc=10.5.6.126^action=notified^cncHost=xxx.xxx.xxx.xxx^externalId=84^devTime=Oct 16 2020 14:36:12
UTC^sid=84400123^cncPort=80^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=84^src=xxx.xxx.xxx.xxx^cncChannel=GET http://yy8311.com/?/goods_list/14_25_0 HTTP/1.1::~~Host:
yy8311.com::~~/7^{xd_.4\=k]}xFs`kz{\\y[OdGp7y{g xa%k_M?~}oxcx\\{\|Z_h~x8?t\|m_Od0\\GA_
{O\=Q}G/UG+;po\\G/v^pupnp;]\=\|\={~/yNV\|x\|[_\\S/]c^]/\|ic}[6 7Z_`c8]{r\=;_u7\=~o.5W62>4w_s>X)cQ>zk^%O?EO])-
a4q8C[WO{gwx*;?~?{{?][p^{gg{~_y\|}okak/iz<gk?.?qW::UnID.1L31fxL~~y4 mo::[W}{_}+w_yk9~]<N?88^}]:96h~"4_~Uy/?v<6X
{l?cQW?+<zzyn?>x,O\=>7?'>xy_y{t?>}W>%KY-<G\|iiU 94pnPZgs[yN!\=b9\=47%u^g+G(kRGe>e?CNGc\\B2O2mmgO};e[^s
(jbMOZV^start=Oct 16 2020 14:36:12 UTC^uuid=6d8cfac0-549b-45f4-9781-72bf2873441d^ .

infection-match (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|infectionmatch|
sev=1^srcMAC=92:73:75:00:00:35^request=hxxp://exe.xinniankl.com/014.exe^srcPort=1165^shost=119-168-188-
108.rev.home.ne.jp^proto=tcp^dst=151.141.197.29^cncHost=151.141.197.29^externalId=70184^sid=600144^cncChannel=G
ET /014.exe HTTP/1.1::~~Accept: */*::~~Accept-Encoding: gzip, deflate::~~User-Agent: Mozilla/4.0 (compatible;
MSIE 6.0; Windows NT 5.1; SV1)::~~Host: exe.xinniankl.com::~~Connection: Keep-
Alive::~~::~~^sname=Local.Infection^vlan=0^dvchost=abc^cncPort=80^link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_
id\=70184^dstPort=80^src=119.168.188.108^dstMAC=00:19:d1:fd:a2:52^dvc=10.5.6.238^devTime=Jun 28 2020 09:02:20
UTC^action=notified^uuid=faf9e427-135f-4eef-9abe-7434b4c1c1bc^

malware-callback (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|malwarecallback|
sev=7^dstPort=443^sname=Trojan.Gootkit^dvchost=abc.mrl.trellix.com^srcMAC=00:0c:29:75:37:4a^proto=tcp^
srcPort=49193^dst=xx.xxx.xxx.xxx^vlan=0^dstMAC=00:50:56:fe:a1:97^dvc=10.5.6.126^action=notified^cncHost=49.130.
180.155^externalId=88^devTime=Oct 16 2020 14:36:29
UTC^sid=86112670^cncPort=443^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=88^src=xx.xxx.xxx.xxx^cncChannel=^start=Oct 16 2020 14:36:29 UTC^uuid=37031d85-101b-460f-9e30-6e0117c089f6^
.

malware-callback (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|malwarecallback|
sev=9^dstPort=8080^sname=Trojan.APT.PingBed^dvchost=xxxx^srcMAC=00:0c:29:ec:df:a4^proto=tcp^srcPort=55
689^dst=xxx.xx.x.xx^vlan=0^dstMAC=00:50:56:be:42:a6^request=hxxp://colville.com/Gallery/Winterfest/2.jpg^dvc=xx
.x.x.xxx^action=notified^cncHost=xxx.xx.x.xx^externalId=70252^devTime=Jun 29 2020 07:00:34
UTC^sid=33351211^cncPort=8080^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=70252^src=xxx.xx.x.xx^cncChannel=GET http://colville.com/Gallery/Winterfest/2.jpg HTTP/1.1::~~User-Agent:
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; #1atEW5tuNDl0kt579c9.BMWUS)::~~Host:
Colville.com::~~Pragma: no-cache::~~::~~^uuid=cc348b62-c628-4c82-8c26-93b8df823cec^

web-infection (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916248|web-infection|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0113^sev=4^dstPort=80^sname=Malware.Binary.url^shost=xxx-xxx-xxxxxx.
rev.home.ne.jp^srcMAC=92:73:75:00:00:35^targetApp=InternetExplorer
6.0^dvchost=abc.mrl.trellix.com^dst=xxx.xxx.xxx.xxx^vlan=0^srcPort=1144^dvc=xx.x.x.xxx^externalId=56^devTime=Ju
n 29 2020 08:39:00 UTC^action=notified^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?inc_
id\=56^filePath=s101-cnzz.com/index.htm^src=xxx.xxx.xxx.xxx^anomaly=98304^uuid=e7325891-cfd2-4a7b-8f3cf0b97e0b5a6a^
.

web-infection (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|web-infection|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0113^sev=4^srcMAC=d6:96:0a:84:24:15^srcPort=1057^src=67.218.73.59^shost=67-
21859.dyn.actaccess.net^proto=tcp^dst=xx.xx.xxx.xxx^cncHost=xisock.com^externalId=151^sid=86115851^sname=Exploi
t.Browser^filePath=yipinlawyer.com/^vlan=0^dvchost=Honeybee^cncPort=443^link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?inc_id\=151^dstPort=80^targetApp=InternetExplorer 8.0^dvc=xx.x.x.xxx^devTime=Jun 29 2020
05:47:41 UTC^action=notified^uuid=3a6365a4-4855-4919-86d5-7ff7d147cde2^ .

malware-object (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|web-infection|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0114^sev=4^srcMAC=6a:c0:02:9a:9b:7d^srcPort=1058^src=116.184.120.214^proto=tcp^dst=xxx.xxx.xxx.xxx^cncHost=f
getcareer.
com^externalId=4079^sid=86115851^anomaly=98305^cncChannel=\\000\\377\\001\\000\\000\\000^sname=HTML.Infe
ctor.Ramnit^filePath=yy8311.com/?/goods_list/14_25_
0^vlan=0^dvchost=abc.mrl.trellix.com^cncPort=443^link=https://abc.mrl.trellix.com/event_stream/events_for_
bot?inc_id\=4079^dstPort=80^targetApp=InternetExplorer 8.0^dvc=xx.x.x.xxx^devTime=Oct 16 2020 14:41:43
UTC^action=notified^start=Oct 16 2020 14:36:12 UTC^uuid=bb17f03e-649d-451f-a43c-519e6301fbbb^ .

malware-object (Email Security)

LEEF:1.0|Trellix|eMPS|9.0.2.925255|malware-object|osinfo=Microsoft Windows7 64-bit 6.1 sp1
17.0114^sev=4^sname=fe_ml_heuristic^proto=tcp^fileHash=ebe52c916b26694796abef44b154e58e^filePath=.........
............... ............... ............ .........^vlan=0^dvchost=abc-
123.mrl.trellix.com^dvc=xx.x.x.xxx^cncChannel=POST xezlifewvupazah.ws HTTP/1.1::~~User-Agent: Mozilla/4.0
(compatible; msie 40; NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR
00000000/00000000)::~~::~~^duser=samples@tesoro.com^cncPort=80^cncHost=xezlifewvupazah.ws^externalId=20^devTime
=Oct 22 2020 07:33:36 UTC^suser=sample@tesoro.com^msg=51790836-a876-32aa-a2dbe6e0023e0230@
tesoro.com^link=https://abc-123.mrl.trellix.com/emps/eanalysis?e_
id\=12&type\=attch^sid=33351836^anomaly=99329^action=blocked^start=Oct 22 2020 07:30:24 UTC^uuid=68c16bee-87d4-
44e4-a098-ee58a55aeb44^sha256sum=83920de959a29be45ff40a3f513f7ec94ad21433e009a3f9e36dea44a8d42b45^subject=mal
sample :: original^ .

malware-object (Malware Analysis)

LEEF:1.0|Trellix|MAS|9.0.0.916210|malware-object|osinfo=Microsoft Windows10 64-bit 10.0 base
17.0112^sev=4^sname=Malware.Binary.pd
f^fileHash=c7dfb7a02563dd44892943d175a82327^filePath=/data/ma/share/source_mas/50.pdf^vlan=0^dvchost=xx-xxxxx.
eng.trellix.com^dvc=xxx.xx.xxx.xx^externalId=15744^devTime=Jun 23 2020 07:38:14 Z^actio
n=notified^link=https://xx-xxx-xx.eng.trellix.com/malware_analysis/analyses?maid\=15744^anomaly=miscanomaly^
uuid=fb25fbba-9ec9-4c9a-9e34-d47b0a1e2e63^sha256sum=e66c20b6777aa59d8d2b8277818772b9acf50
f172cf3e1949e420ebe242c9162^

malware-object (File Protect)

LEEF:1.0|Trellix|fMPS|9.0.0.916210|malware-object|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112^sev=4^sname=fe_ml_
heuristic^proto=udp^fileHash=434da9ab51c3f9e70b7611bd70cc9e52^filePath=/data/ma/notify/Malware_
Sample135^vlan=0^dvchost=xx-xxxxx.
eng.trellix.com^dvc=xx.xxx.xx.xxx^action=notified^cncHost=xx.xx.xx.xx^externalId=92^devTime=Jun 26 2020
17:06:53 UTC^sid=86107514^cncPort=7455^link=https://xx.xxx.xx.xxx/fmps/fanalysis?ma_id\\=92&lms_
iden\\=0CC47AA8FFA6^anomaly=98304^uuid=6f9b2f1a-c4e8-4a29-b4b9-
18aae8d523b7^sha256sum=b9f2ff8fff7bb0238ee9a040f37807b18fe07e4788c71025b279a60edf82a1cb^\

malware-object (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|malware-object|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112^sev=4^sname=fe_ml_heuristic^fileHash=83f8be9e83de5543794c4ab5aa320875^filePath=/data/ma/notify/Malware_
Sample140^vlan=0^dvchost=xx-xx-xxx^dvc=xx.xxx.xx.xxx^externalId=56^devTime=Jun 26 2020 17:21:54
UTC^action=notified^link=https://abc.eng.trellix.com/fmps/fanalysis?ma_id\\=56^anomaly=98304^uuid=a321b537-
f974-44d5-9909-cb336689f61b^sha256sum=e5b1bc7b67cba05a664107a36dde58f5896355d429430ce8c70753de60e5e3af^\

ips-event (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916432|ips-event|id=12^devTime=Jun 26 2020 13:30:17
GMT^src=xxx.xx.x.xx^srcPort=80^srcMAC=00:17:a4:aa:f4:93^dst=172.16.8.156^dstPort=1043^dstMAC=00:0c:29:b2:fb:4f^
sev=7^sigId=85302399^sigrevision=12^matchcount=1^signame=Microsoft Internet Explorer XML Processing Memory
Corruption^cve_id=^action=notified^attack_mode=client^url=https://abc.mrl.trellix.com/notification_url/ips_
events?ev_id\=12^devTimeFormat=MMM dd yyyy HH:mm:ss z^cat=ipsevent^
mvxStatus=N/A^proto=6^dvc=10.5.6.238^dvchost=abc.mrl.trellix.com

ips-event (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|ips-event|id=15^devTime=Jun 29 2020 08:36:01
GMT^src=xxx.xx.x.x^srcPort=80^srcMAC=00:1b:78:75:79:68^dst=xxx.xx.x.xx^dstPort=33501^dstMAC=00:0c:29:5e:e3:6c^s
ev=7^sigId=85311119^sigrevision=8^matchcount=1^signame=Potential Heap Spray Memory Allocation^cve_
id=^action=notified^attack_mode=client^url=https://abc.mrl.trellix.com/notification_url/ips_events?ev_
id\=15^devTimeFormat=MMM dd yyyy HH:mm:ss z^cat=ipsevent^
mvxStatus=N/A^proto=6^dvc=xx.x.x.xx^dvchost=abc.mrl.trellix.com

riskware-callback (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|riskware-callback|devTime=Jun 29 2020 07:49:43 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=10.0.0.43^dst=xxx.xx.xxx.x^srcPort=1072^dstPort=80^srcMAC=00:20:18:11:01:43^dstMAC=00:01:
6c:a9:2f:27^url=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config^link=https://abc.mrl.trellix.com/detection/objects?uuid=36e8bce0-1f70-44bf-ae14-
90c7946422d7^vlan=0^externalId=380^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.MultiPlug^dvc=10.5.
6.16^uuid=36e8bce0-1f70-44bf-ae14-90c7946422d7^cncChannel=GET /installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config HTTP/1.1::~~Accept-Language: en-XX::~~User-Agent: DownloadMR/1.2.4+ (MSIE 8.0;
Windows NT 5.1 SP3; DB\=ie; 9bf59659-7f5b-02eb-8c69-ce6a8ca6b231; m\=wXuH; u\=admin; aurora)::~~Host:
49939.northstar.api.socdn.com::~~Connection: Keep-Alive::~~::~~^

riskware-infection (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|riskware-callback|devTime=Jun 29 2020 07:49:43 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=xx.x.x.xx^dst=xxx.xx.xxx.x^srcPort=1072^dstPort=80^srcMAC=00:20:18:11:01:43^dstMAC=00:01:
6c:a9:2f:27^url=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config^link=https://abc.mrl.trellix.com/detection/objects?uuid=36e8bce0-1f70-44bf-ae14-
90c7946422d7^vlan=0^externalId=380^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.MultiPlug^dvc=10.5.
6.16^uuid=36e8bce0-1f70-44bf-ae14-90c7946422d7^cncChannel=GET /installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config HTTP/1.1::~~Accept-Language: en-XX::~~User-Agent: DownloadMR/1.2.4+ (MSIE 8.0;
Windows NT 5.1 SP3; DB\=ie; 9bf59659-7f5b-02eb-8c69-ce6a8ca6b231; m\=wXuH; u\=admin; aurora)::~~Host:
49939.northstar.api.socdn.com::~~Connection: Keep-Alive::~~::~~^ .

riskware-object (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916090|riskware-object|devTime=Jun 26 2020 12:30:41 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss z^sev=1^link=https://abc.mrl.trellix.com/detection/objects?uuid=3a523bed-b7d4-4d80-b236-
f0cd3b1b811e^vlan=0^externalId=2483^dvchost=abc.mrl.trellix.com^action=blocked^sname=CustomPolicy.MVX.65003.Exe
cutableDeliveredByEmail.^fileHash=41a0d67ba3833d230f1229ff058be057^filePath=Microsoft_
Corporation.dll^osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112^dvc=10.5.6.174^duser=brownie@tesoro.com^suser=brownie@tesoro.com^msg=3b670a25-15b6-134f-02b3-
d5745ab7722f@tesoro.com^uuid=3a523bed-b7d4-4d80-b236-
f0cd3b1b811e^sha256sum=4f11443a2fa6c714d3e33597f0d08de4e11a6a2fdb7de2e4a01addd5977665c5^subject=Riskware
Object^

riskware-callback (IPv4) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-callback|devTime=Oct 22 2020 08:49:09 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=xx.x.x.xx^dst=xxx.xx.xxx.x^srcPort=1076^dstPort=80^srcMAC=00:20:18:11:01:43^dstMAC=00:01:
6c:a9:2f:27^url=http://stan.mxp533.com/__dmp__
/^link=https://abc.mrl.trellix.com/detection/objects?uuid=9684f196-ec61-4d08-9866-
7f23db30c6db^vlan=0^externalId=120^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.SoftPulse^dvc=xx.x.
x.xxx^uuid=9684f196-ec61-4d08-9866-7f23db30c6db^cncChannel=POST /__dmp__/ HTTP/1.1::~~User-Agent: dBrowser 1
CallGetResponse:1::~~Host: stan.mxp533.com::~~Content-Length: 237::~~Cache-Control: no-cache::~~::~~data\=
{"msg":"Connection failed","url":"","lno":0,"xtra":"","method":"function getResponseFromWrapper
(url,post,callback,failcallback){window.external.getResponse
(url,post,callback,failcallback)}","version":"1.5.7","av":"","fw":"","as":""}^ .

riskware-callback (IPv6) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-callback|devTime=Oct 22 2020 09:15:57 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=2011::1:67e7:bf08^dst=2011::1:3c33:39f1^srcPort=1072^dstPort=80^srcMAC=00:20:18:11:01:43^
dstMAC=00:01:6c:a9:2f:27^url=http://savepop.co.kr/app/download/partner/2/savepop_
agent.exe^link=https://abc.mrl.trellix.com/detection/objects?uuid=0b623598-7795-4ca1-a1a1-
9f2b02ae880b^vlan=0^externalId=771^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.AppCare.Savepop^dvc
=xx.x.x.xxx^uuid=0b623598-7795-4ca1-a1a1-9f2b02ae880b^cncChannel=GET /app/download/partner/2/savepop_agent.exe
HTTP/1.0::~~Host: savepop.co.kr::~~User-Agent: NSISDL/1.2 (Mozilla)::~~Accept: */*::~~::~~^ .

riskware-infection (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|riskware-infection|devTime=Oct 16 2020 14:08:36 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^src=xx.xxx.xxx.xxx^dst=xx.xx.xx.xx^srcPort=50748^dstPort=80^srcMAC=00:50:56:b4:67:9b^dstMAC=a0:d3:c1:f1
:4a:7d^url=172.16.1.2/~kjohnson/CVE-2014-
8439/Exploit.html^link=https://abc.mrl.trellix.com/detection/objects?uuid=ed14f6a4-9796-4dec-9602-
f6ce7cec871f^vlan=0^externalId=4077^dvchost=abc.mrl.trellix.com^action=notified^sname=PUP.Generic.MVX^osinfo=Mi
crosoft Windows7 32-bit 6.1 sp1 17.0114^dvc=xx.x.x.xxx^uuid=ed14f6a4-9796-4dec-9602-f6ce7cec871f^ .

riskware-object (IPv4) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-object|devTime=Oct 22 2020 09:16:39 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^src=xx.xx.xx.xx^dst=xx.xx.xx.xx^srcPort=55059^dstPort=80^srcMAC=10:60:4b:a9:b4:04^dstMAC=10:60:4b:a9:86
:18^url=15.15.15.11/YaraAdware^link=https://abc.mrl.trellix.com/detection/objects?uuid=bdab4b33-6856-40ec-93be-
1b4d7cd5968d^vlan=0^externalId=151^dvchost=abc.mrl.trellix.com^action=notified^sname=FE_Adware_
00fc8020ad243161^fileHash=a5a4de61293d9dba3a46ec7e67f07c30^filePath=YaraAdware^dvc=xx.x.x.xxx^uuid=bdab4b33-
6856-40ec-93be-1b4d7cd5968d^sha256sum=25b8e3cc4774975876c36de3a6e5a34bb7a48857e4f02c36416aed7631d03094^protoheader=
GET /YaraAdware HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host:
15.15.15.11::~~Connection: Keep-Alive::~~HTTP/1.1 200 OK::~~Date: Mon, 12 Oct 2015 17:14:02 GMT::~~Server:
Apache/2.2.15 (CentOS)::~~Last-Modified: Wed, 30 Sep 2015 19:59:50 GMT::~~ETag: "194077b-ba988-
520fc5f8cfd9d"::~~Accept-Ranges: bytes::~~Content-Length: 764296::~~Connection: close::~~Content-Type:
text/plain; charset\=UTF-8::~~^ .

riskware-object (IPv6) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-object|devTime=Oct 22 2020 09:43:47 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^src=2011::1:4d84:9b6e^dst=2011::1:13f5:7d67^srcPort=50998^dstPort=80^srcMAC=d8:9d:67:17:19:71^dstMAC=d8
:9d:67:17:24:75^url=xx.x.x.xx/30dbe64027e570ada595c1e7b89664db.zip^link=https://abc.mrl.trellix.com/detection/o
bjects?uuid=68119bb0-bf35-4124-9af3-
13c27c7ebdaa^vlan=0^externalId=224^dvchost=abc.mrl.trellix.com^action=notified^sname=FE_Adware_
Searchbar^fileHash=904478b16474f63737389b8244a66dca^filePath=30dbe64027e570ada595c1e7b89664db.zip^dvc=xx.x.x.xx
x^uuid=68119bb0-bf35-4124-9af3-
13c27c7ebdaa^sha256sum=ea74197e0337a03dd6c2565d37d37dec2e0595747b99db3f4094a686f06ef390^proto-header=GET
/30dbe64027e570ada595c1e7b89664db.zip HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host:
xx.x.x.xx::~~Connection: Keep-Alive::~~HTTP/1.1 200 OK::~~Date: Wed, 14 Oct 2015 17:52:23 GMT::~~Server:
Apache/2.2.15 (CentOS)::~~Last-Modified: Wed, 14 Oct 2015 17:50:19 GMT::~~ETag: "380415-43c3-
52214321e1b2a"::~~Accept-Ranges: bytes::~~Content-Length: 1^ .

riskware-object (Email Security)

LEEF:1.0|Trellix|eMPS|9.0.2.925255|riskware-object|devTime=Oct 22 2020 10:09:29 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss z^sev=1^link=https://abc-123.mrl.trellix.com/detection/objects?uuid=8c145d59-3b5e-4bab-b628-
f88476ba092c^vlan=0^externalId=29^dvchost=abc-
123.mrl.trellix.com^action=blocked^sname=Adware.FileTour^fileHash=23780117a00b9b3526c3a0a3ea7c590f^filePath=Bot
tCom_riskware1.exe^osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0114^dvc=xx.x.x.xxx^duser=samples@tesoro.com^suser=sample@tesoro.com^msg=33fe63a5-eba7-8bb4-98fa-
31b41cc38d25@tesoro.com^uuid=8c145d59-3b5e-4bab-b628-
f88476ba092c^sha256sum=c78be5b7b2bcb2c69ae2c1d161a2f89710638f852ddabbce0f8f675272d559e4^subject=Riskware
blocked :: original^cncChannel=GET /php/track1.php HTTP/1.0::~~Host: soft.freemusicdownloads.world::~~User-
Agent: InnoTools_Downloader::~~::~~^ .

SmartVision (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916432|smartvision-event|^devTime=Jun 26 2020 12:42:06 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss z^externalId=1^action=notified^sid=91500000^sigrevision=5^sev=5^uuid=20281250-7c27-4cce-a410-
2f04e1002c6e^name=Suspicious Remote Scheduled Task Activity^cat=T1053 / Remote Execution^msg=Suspicious Remote
Scheduled Task
Activity^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^link=https://abc.mrl.trellix.com/notificatio
n_url?uuid\=20281250-7c27-4cce-a410-2f04e1002c6e^ LEEF:1.0|Trellix|MPS|9.0.0.916432|smartvision-baseevent|^
devTime=Jun 26 2020 12:42:07 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss z^eventId=1^alertId=1^name=SMB
Create Request: Delete file in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|s
martvision-base-event|^devTime=Jun 26 2020 12:42:06 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=2^alertId=1^name=SMB Create Request: File in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|smartvision-base-event|^devTime=Jun 26 2020 12:42:07
UTC^devTimeFormat=MMM dd yyyy HH:mm:ss z^eventId=3^alertId=1^name=ATSVC Start
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|s
martvision-base-event|^devTime=Jun 26 2020 12:42:07 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=4^alertId=1^name=ATSVC Delete
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|s
martvision-base-event|^devTime=Jun 26 2020 12:42:06 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=5^alertId=1^name=ATSVC Add Job: cmd.exe /C with
redirect^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA

SmartVision (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|smartvision-base-event|^devTime=Jun 29 2020 08:13:34 UTC^devTimeFormat=MMM dd
yyyy HH:mm:ss z^eventId=12^alertId=7^name=ATSVC Add Job: cmd.exe /C with
redirect^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|smartvision-base-event|^devTime=Jun 29 2020 08:13:35
UTC^devTimeFormat=MMM dd yyyy HH:mm:ss z^eventId=14^alertId=7^name=ATSVC Start
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|s
martvision-base-event|^devTime=Jun 29 2020 08:13:35 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=15^alertId=7^name=ATSVC Delete
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|s
martvision-base-event|^devTime=Jun 29 2020 08:13:35 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=11^alertId=7^name=SMB Create Request: Delete file in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|s
martvision-base-event|^devTime=Jun 29 2020 08:13:34 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=13^alertId=7^name=SMB Create Request: File in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|smartvision-event|^devTime=Jun 29 2020 08:13:34
UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^externalId=7^action=notified^sid=91500000^sigrevision=5^sev=5^uuid=5985dbd8-5066-4e04-b560-
3f05c93506d6^name=Suspicious Remote Scheduled Task Activity^cat=T1053 / Remote Execution^msg=Suspicious Remote
Scheduled Task
Activity^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^link=https://abc.mrl.trellix.com/notificatio
n_url?uuid\=5985dbd8-5066-4e04-b560-3f05c93506d6^