This topic covers the following information:
About the Hosts tab
Fields in the Hosts tab
Details for a victim-specific alert grouping on
About the Hosts tab
An IPS platform offers three views of malware events. Two of the views list malware alerts (both MVX-verified malware events and MVX-correlated IPS events), and the third view lists callback activity associated with malware. When you choose Alerts > Alerts, the Hosts tab is selected by default.
The Hosts tab lists all malware alerts and IPS alerts, grouped by victim IP address and attack rule name. Multiple alerts associated with the same victim and signature rule are combined in a single entry in the list. The Total field displays the number of alerts represented by an entry.
Fields in the Hosts tab
The Hosts tab lists MVX-verified events that occurred within the selected time frame, consolidated by victim IP address, and sorted in reverse chronological order. On an IPS platform, the list includes IPS events and can include acknowledged IPS alerts.
The following table describes the fields in this view alerts grouped by victim.
Column | Description |
|---|---|
| Click to expand the row to display additional results |
Host | IP address of the infected host. |
Severity | The icon represents the event severity level. Event severity estimates the likelihood that the targeted host was compromised by the event. The following types of icons are used:
A row of 7 to 10 red dots indicates a Critical severity (levels 7 ‑ 10).
A row of 4 to 6 orange dots indicates a Major severity (levels 4 ‑ 6).
A row of 1 to 3 amber dots indicates a Minor severity (levels 1 ‑ 3). |
Total | Total number of malware alerts (infections and callbacks) and IPS alerts for this infected host. If you want to go to a view of the Alerts tab that has been filtered to show the individual alerts for the infected host, click the linked text. |
Infections | Number of infections for this host. |
Callbacks | Number of malware callback infections for this host, including signature matches and communications with the botnet server. |
Blocked | Number of events that were blocked by appliance inline blocking. |
Last malware | Last type of malware or attack involved in this infected host. To display a detailed description of this type of attack, click the linked text. Detailed descriptions are not available for attacks detected by custom IPS rules. |
Last seen at | Date and time of the most recent attack on the host. |
Host name | Last host name associated with the network host that sent the attack, if known. |
Last acknowledgement at | Date and time of the most recent acknowledgment of this alert |
Badges | On an IPS platform, this column displays badges that indicate analysis of alerts represented by the entry:
The IPS badge means that the entry represents one or more IPS alerts. For more information, see the following topics: ● Malware events and IPS events ● IPS event and alert management
The Data Theft badge means that the entry represents one or more non-IPS alerts in which data theft occurred. If you want to go to a view of the Hosts tab that has been filtered to list the individual alerts for the infected host, click the badge. For more information, see the Network Security User Guide. |
Badges | On any Network Security appliance enabled for Advanced Threat Analysis (ATI), Threat Info badges can appear in this column. The color of the badge indicates the level of risk that the threat poses to your network.
A red badge indicates an ATI alert for a threat that poses a high risk.
An orange Threat Info badge indicates an ATI alert for a threat that poses a medium level of risk.
An amber Threat Info badge indicates an ATI alert for a threat that poses a low risk to your network. For managed Network Security appliances, ATI badges and ATI information are visible from the Central Management System Web UI only. For more information about ATI, see the Network Security User Guide. For an ATI alert, the threat level measures the level of risk posed by the attack against the targeted organization. This score is based on the malware's behavioral capabilities and intent, threat actor profiles, and other FireEye intelligence as available. The ATI threat level determination for an ATI alert is different from the threat severity for an alert. The severity estimates the likelihood that the targeted host has been compromised by an event. For example, established command and control (CnC) channels result in highest severity, while host connection to a compromised site is low severity because it does not indicate whether the host was breached. |
Times are displayed in UTC format by default. To set the time zone, choose Settings > Date and Time.
You can filter the list on a single column. Click Show / Hide Filters to show or hide filter options for each column.
To filter the list on one or more types of badges, open the Select Badge(s) list, select the types of badges you want to include, then click Apply.
For all other columns, type the text you want to match and then press Enter.
Details for a victim-specific alert grouping
To display detailed information about any entry listed in the Hosts tab, you can expand the view of the entry by clicking the triangle icon in the left-most column of that row. The drill-down view displays the following information about the infected host (attack victim):
Field | Description |
|---|---|
Malicious capabilities observed in the VM | |
Data theft | Number of items that were stolen or targeted for theft. |
Malicious behavior | Type of malware activity that is observed. |
OS change summary | Operating system changes that are made by the malware. |
Malware detected | |
Malware | Type of malware involved in the infection. |
Severity | Severity level of the event. |
Total | Total number of alerts involving the specified malware family. Click the link to display a list of individual alerts on this host that are related to the same malware family. |
Infections | Number of infections that are confirmed on the MVX engine. |
Callbacks | Number of events that involved communication with a remote command and control (CnC) server. |
Blocked | Number of events that were blocked by appliance inline blocking. |
Botnets | Number of events involving botnets. |
Last CnC server | Remote CnC server. |
Last location | CnC server location, if known. |
First seen | First time that an infection event for this malware family was recorded for this host. |
Last seen | Last time that an infection event for this malware family was recorded for this host. |
Ports used | Ports used in the attack. |
Protocols | Protocols used in the attack. |
Infection URLs (the first 10 URLs that infected the victim) | |
| Click the arrow to the left of a URL to display the URLs to which the user was directed as a result of the initial infection. The original (first) URL that was visited is shown in bold. |
Initial infection URL | Original (first) URL visited by the victim. |
# Visits | Number of times the infected host has visited the same infection URL |
Total URLs | Total number of URLs to which the user was redirected. |
First URL at | Time at which the first URL was reached. |
Last URL at | Time at which the last URL was reached. |
Malware binaries (the first 10 URLs that infected the victim) | |
Md5sum | MD5 checksum result. Expand for protocol headers. |
Filetype | Type of file analyzed from the traffic stream. File types include the following:
For more information, see the Network Security User Guide. |
Protocol | Protocol involved. |
Encoding | Encoding used. |
Last analysis time | Most recent time when the checksum was performed. |
# Occurrences | Number of checksum activities. |
Acknowledge the infections and callbacks above for the host at ip‑address | |
| Click to expose the notes text box and the Acknowledge button for this alert. For more information about acknowledging an IPS alert, see the Network Security User Guide. |








