web-infection (Network Security on Central Management)

Prev Next
CEF:0|Trellix|CMS|9.0.0.916210|WI|web-infection|4|rt=Jun 29 2020 05:47:41 UTC src=xx.xxx.xx.xx cn3Label=cncPort
cn3=443 cn2Label=sid cn2=86115851 shost=xx-xxx-xx-xx.dyn.actaccess.net dproc=InternetExplorer 8.0
cs5Label=cncHost cs5=xisock.com spt=1057 cs3Label=osinfo cs3=Microsoft WindowsXP 32-bit 5.1 sp3 17.0113
proto=tcp dvchost=axhwmps dvc=xx.x.x.xxx smac=d6:96:0a:84:24:15 cn1Label=vlan cn1=0 dpt=80 externalId=151
cs4Label=link cs4=https://abc.mrl.trellix.com/event_stream/events_for_bot?inc_id\=151 act=notified
filePath=yipinlawyer.com/ dst=xx.xx.xxx.xxx cs1Label=sname cs1=Exploit.Browser
devicePayloadId=3a6365a4-4855-4919-86d5-7ff7d147cde2