The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sample LEEF notifications per event type

Prev Next

Sample LEEF notifications are shown for various event types. The definitions for each of the <extension> field keys are provided in LEEF extension field key=value pair definitions.

Note

The product names in notifications are ‘MPS’ (for Network Security), ‘eMPS’ (for Email Security — Server Edition) ‘fMPS’ (for File Protect), ‘MAS’ (for Malware Analysis), and ‘CMS’ (for Central Management).

domain-match (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916248|domain-match|sev=1^sname=Trojan.Win32.Dogrobot.gen.E^shost=xxx-xxx-xxxxxx.
rev.home.ne.jp^srcMAC=92:73:75:00:00:35^proto=udp^srcPort=1025^vlan=0^dstMAC=00:19:d1:fd:a2:52^dvc=xx.x.x.x
xx^action=notified^dvchost=abc.mrl.trellix.com^cncHost=the.microgood.net^externalId=226^devTime=Jun 29 2020
08:35:55 UTC^sid=89017273^cncPort=53^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=226^filePath=the.microgood.net^src=xxx.xxx.xxx.xxx^uuid=1a250f4b-bd82-4828-9752-4e2ffff8bdf2^

domain-match (Network Security on Central Management)

LEEF:1.0|Trellix|MPS|9.0.2.924861|domainmatch|
sev=1^sname=Trojan.Ramnit.SNK.DNS^dvchost=abc.mrl.trellix.com^srcMAC=6a:c0:02:9a:9b:7d^proto=udp^srcPort=
1070^vlan=0^dstMAC=00:50:56:e5:3f:c5^dvc=xx.x.x.xxx^action=notified^cncHost=fgetcareer.
com^externalId=85^devTime=Oct 16 2020 14:36:16
UTC^sid=80461038^cncPort=53^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=85^filePath=fget-career.com^src=xxx.xxx.xxx.xxx^start=Oct 16 2020 14:36:16 UTC^uuid=95846ab0-a464-43e1-
a89f-9a0e51f3a4b1^ .

infection-match (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|infectionmatch|
sev=1^dstPort=80^sname=Worm.Ramnit^dvchost=abc.mrl.trellix.com^srcMAC=6a:c0:02:9a:9b:7d^proto=tcp^srcPort
=1058^dst=xxx.xxx.xxx.xxx^vlan=0^dstMAC=00:50:56:e5:3f:c5^request=hxxp://yy8311.com/?/goods_list/14_25_
0^dvc=10.5.6.126^action=notified^cncHost=xxx.xxx.xxx.xxx^externalId=84^devTime=Oct 16 2020 14:36:12
UTC^sid=84400123^cncPort=80^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=84^src=xxx.xxx.xxx.xxx^cncChannel=GET http://yy8311.com/?/goods_list/14_25_0 HTTP/1.1::~~Host:
yy8311.com::~~/7^{xd_.4\=k]}xFs`kz{\\y[OdGp7y{g xa%k_M?~}oxcx\\{\|Z_h~x8?t\|m_Od0\\GA_
{O\=Q}G/UG+;po\\G/v^pupnp;]\=\|\={~/yNV\|x\|[_\\S/]c^]/\|ic}[6 7Z_`c8]{r\=;_u7\=~o.5W62>4w_s>X)cQ>zk^%O?EO])-
a4q8C[WO{gwx*;?~?{{?][p^{gg{~_y\|}okak/iz<gk?.?qW::UnID.1L31fxL~~y4 mo::[W}{_}+w_yk9~]<N?88^}]:96h~"4_~Uy/?v<6X
{l?cQW?+<zzyn?>x,O\=>7?'>xy_y{t?>}W>%KY-<G\|iiU 94pnPZgs[yN!\=b9\=47%u^g+G(kRGe>e?CNGc\\B2O2mmgO};e[^s
(jbMOZV^start=Oct 16 2020 14:36:12 UTC^uuid=6d8cfac0-549b-45f4-9781-72bf2873441d^ .

infection-match (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|infectionmatch|
sev=1^srcMAC=92:73:75:00:00:35^request=hxxp://exe.xinniankl.com/014.exe^srcPort=1165^shost=119-168-188-
108.rev.home.ne.jp^proto=tcp^dst=151.141.197.29^cncHost=151.141.197.29^externalId=70184^sid=600144^cncChannel=G
ET /014.exe HTTP/1.1::~~Accept: */*::~~Accept-Encoding: gzip, deflate::~~User-Agent: Mozilla/4.0 (compatible;
MSIE 6.0; Windows NT 5.1; SV1)::~~Host: exe.xinniankl.com::~~Connection: Keep-
Alive::~~::~~^sname=Local.Infection^vlan=0^dvchost=abc^cncPort=80^link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_
id\=70184^dstPort=80^src=119.168.188.108^dstMAC=00:19:d1:fd:a2:52^dvc=10.5.6.238^devTime=Jun 28 2020 09:02:20
UTC^action=notified^uuid=faf9e427-135f-4eef-9abe-7434b4c1c1bc^

malware-callback (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|malwarecallback|
sev=7^dstPort=443^sname=Trojan.Gootkit^dvchost=abc.mrl.trellix.com^srcMAC=00:0c:29:75:37:4a^proto=tcp^
srcPort=49193^dst=xx.xxx.xxx.xxx^vlan=0^dstMAC=00:50:56:fe:a1:97^dvc=10.5.6.126^action=notified^cncHost=49.130.
180.155^externalId=88^devTime=Oct 16 2020 14:36:29
UTC^sid=86112670^cncPort=443^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=88^src=xx.xxx.xxx.xxx^cncChannel=^start=Oct 16 2020 14:36:29 UTC^uuid=37031d85-101b-460f-9e30-6e0117c089f6^
.

malware-callback (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|malwarecallback|
sev=9^dstPort=8080^sname=Trojan.APT.PingBed^dvchost=xxxx^srcMAC=00:0c:29:ec:df:a4^proto=tcp^srcPort=55
689^dst=xxx.xx.x.xx^vlan=0^dstMAC=00:50:56:be:42:a6^request=hxxp://colville.com/Gallery/Winterfest/2.jpg^dvc=xx
.x.x.xxx^action=notified^cncHost=xxx.xx.x.xx^externalId=70252^devTime=Jun 29 2020 07:00:34
UTC^sid=33351211^cncPort=8080^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id\=70252^src=xxx.xx.x.xx^cncChannel=GET http://colville.com/Gallery/Winterfest/2.jpg HTTP/1.1::~~User-Agent:
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; #1atEW5tuNDl0kt579c9.BMWUS)::~~Host:
Colville.com::~~Pragma: no-cache::~~::~~^uuid=cc348b62-c628-4c82-8c26-93b8df823cec^

web-infection (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916248|web-infection|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0113^sev=4^dstPort=80^sname=Malware.Binary.url^shost=xxx-xxx-xxxxxx.
rev.home.ne.jp^srcMAC=92:73:75:00:00:35^targetApp=InternetExplorer
6.0^dvchost=abc.mrl.trellix.com^dst=xxx.xxx.xxx.xxx^vlan=0^srcPort=1144^dvc=xx.x.x.xxx^externalId=56^devTime=Ju
n 29 2020 08:39:00 UTC^action=notified^link=https://abc.mrl.trellix.com/event_stream/events_for_bot?inc_
id\=56^filePath=s101-cnzz.com/index.htm^src=xxx.xxx.xxx.xxx^anomaly=98304^uuid=e7325891-cfd2-4a7b-8f3cf0b97e0b5a6a^
.

web-infection (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|web-infection|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0113^sev=4^srcMAC=d6:96:0a:84:24:15^srcPort=1057^src=67.218.73.59^shost=67-
21859.dyn.actaccess.net^proto=tcp^dst=xx.xx.xxx.xxx^cncHost=xisock.com^externalId=151^sid=86115851^sname=Exploi
t.Browser^filePath=yipinlawyer.com/^vlan=0^dvchost=Honeybee^cncPort=443^link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?inc_id\=151^dstPort=80^targetApp=InternetExplorer 8.0^dvc=xx.x.x.xxx^devTime=Jun 29 2020
05:47:41 UTC^action=notified^uuid=3a6365a4-4855-4919-86d5-7ff7d147cde2^ .

malware-object (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|web-infection|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0114^sev=4^srcMAC=6a:c0:02:9a:9b:7d^srcPort=1058^src=116.184.120.214^proto=tcp^dst=xxx.xxx.xxx.xxx^cncHost=f
getcareer.
com^externalId=4079^sid=86115851^anomaly=98305^cncChannel=\\000\\377\\001\\000\\000\\000^sname=HTML.Infe
ctor.Ramnit^filePath=yy8311.com/?/goods_list/14_25_
0^vlan=0^dvchost=abc.mrl.trellix.com^cncPort=443^link=https://abc.mrl.trellix.com/event_stream/events_for_
bot?inc_id\=4079^dstPort=80^targetApp=InternetExplorer 8.0^dvc=xx.x.x.xxx^devTime=Oct 16 2020 14:41:43
UTC^action=notified^start=Oct 16 2020 14:36:12 UTC^uuid=bb17f03e-649d-451f-a43c-519e6301fbbb^ .

malware-object (Email Security)

LEEF:1.0|Trellix|eMPS|9.0.2.925255|malware-object|osinfo=Microsoft Windows7 64-bit 6.1 sp1
17.0114^sev=4^sname=fe_ml_heuristic^proto=tcp^fileHash=ebe52c916b26694796abef44b154e58e^filePath=.........
............... ............... ............ .........^vlan=0^dvchost=abc-
123.mrl.trellix.com^dvc=xx.x.x.xxx^cncChannel=POST xezlifewvupazah.ws HTTP/1.1::~~User-Agent: Mozilla/4.0
(compatible; msie 40; NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR
00000000/00000000)::~~::~~^duser=samples@tesoro.com^cncPort=80^cncHost=xezlifewvupazah.ws^externalId=20^devTime
=Oct 22 2020 07:33:36 UTC^suser=sample@tesoro.com^msg=51790836-a876-32aa-a2dbe6e0023e0230@
tesoro.com^link=https://abc-123.mrl.trellix.com/emps/eanalysis?e_
id\=12&type\=attch^sid=33351836^anomaly=99329^action=blocked^start=Oct 22 2020 07:30:24 UTC^uuid=68c16bee-87d4-
44e4-a098-ee58a55aeb44^sha256sum=83920de959a29be45ff40a3f513f7ec94ad21433e009a3f9e36dea44a8d42b45^subject=mal
sample :: original^ .

malware-object (Malware Analysis)

LEEF:1.0|Trellix|MAS|9.0.0.916210|malware-object|osinfo=Microsoft Windows10 64-bit 10.0 base
17.0112^sev=4^sname=Malware.Binary.pd
f^fileHash=c7dfb7a02563dd44892943d175a82327^filePath=/data/ma/share/source_mas/50.pdf^vlan=0^dvchost=xx-xxxxx.
eng.trellix.com^dvc=xxx.xx.xxx.xx^externalId=15744^devTime=Jun 23 2020 07:38:14 Z^actio
n=notified^link=https://xx-xxx-xx.eng.trellix.com/malware_analysis/analyses?maid\=15744^anomaly=miscanomaly^
uuid=fb25fbba-9ec9-4c9a-9e34-d47b0a1e2e63^sha256sum=e66c20b6777aa59d8d2b8277818772b9acf50
f172cf3e1949e420ebe242c9162^

malware-object (File Protect)

LEEF:1.0|Trellix|fMPS|9.0.0.916210|malware-object|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112^sev=4^sname=fe_ml_
heuristic^proto=udp^fileHash=434da9ab51c3f9e70b7611bd70cc9e52^filePath=/data/ma/notify/Malware_
Sample135^vlan=0^dvchost=xx-xxxxx.
eng.trellix.com^dvc=xx.xxx.xx.xxx^action=notified^cncHost=xx.xx.xx.xx^externalId=92^devTime=Jun 26 2020
17:06:53 UTC^sid=86107514^cncPort=7455^link=https://xx.xxx.xx.xxx/fmps/fanalysis?ma_id\\=92&lms_
iden\\=0CC47AA8FFA6^anomaly=98304^uuid=6f9b2f1a-c4e8-4a29-b4b9-
18aae8d523b7^sha256sum=b9f2ff8fff7bb0238ee9a040f37807b18fe07e4788c71025b279a60edf82a1cb^\

malware-object (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|malware-object|osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112^sev=4^sname=fe_ml_heuristic^fileHash=83f8be9e83de5543794c4ab5aa320875^filePath=/data/ma/notify/Malware_
Sample140^vlan=0^dvchost=xx-xx-xxx^dvc=xx.xxx.xx.xxx^externalId=56^devTime=Jun 26 2020 17:21:54
UTC^action=notified^link=https://abc.eng.trellix.com/fmps/fanalysis?ma_id\\=56^anomaly=98304^uuid=a321b537-
f974-44d5-9909-cb336689f61b^sha256sum=e5b1bc7b67cba05a664107a36dde58f5896355d429430ce8c70753de60e5e3af^\

ips-event (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916432|ips-event|id=12^devTime=Jun 26 2020 13:30:17
GMT^src=xxx.xx.x.xx^srcPort=80^srcMAC=00:17:a4:aa:f4:93^dst=172.16.8.156^dstPort=1043^dstMAC=00:0c:29:b2:fb:4f^
sev=7^sigId=85302399^sigrevision=12^matchcount=1^signame=Microsoft Internet Explorer XML Processing Memory
Corruption^cve_id=^action=notified^attack_mode=client^url=https://abc.mrl.trellix.com/notification_url/ips_
events?ev_id\=12^devTimeFormat=MMM dd yyyy HH:mm:ss z^cat=ipsevent^
mvxStatus=N/A^proto=6^dvc=10.5.6.238^dvchost=abc.mrl.trellix.com

ips-event (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|ips-event|id=15^devTime=Jun 29 2020 08:36:01
GMT^src=xxx.xx.x.x^srcPort=80^srcMAC=00:1b:78:75:79:68^dst=xxx.xx.x.xx^dstPort=33501^dstMAC=00:0c:29:5e:e3:6c^s
ev=7^sigId=85311119^sigrevision=8^matchcount=1^signame=Potential Heap Spray Memory Allocation^cve_
id=^action=notified^attack_mode=client^url=https://abc.mrl.trellix.com/notification_url/ips_events?ev_
id\=15^devTimeFormat=MMM dd yyyy HH:mm:ss z^cat=ipsevent^
mvxStatus=N/A^proto=6^dvc=xx.x.x.xx^dvchost=abc.mrl.trellix.com

riskware-callback (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|riskware-callback|devTime=Jun 29 2020 07:49:43 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=10.0.0.43^dst=xxx.xx.xxx.x^srcPort=1072^dstPort=80^srcMAC=00:20:18:11:01:43^dstMAC=00:01:
6c:a9:2f:27^url=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config^link=https://abc.mrl.trellix.com/detection/objects?uuid=36e8bce0-1f70-44bf-ae14-
90c7946422d7^vlan=0^externalId=380^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.MultiPlug^dvc=10.5.
6.16^uuid=36e8bce0-1f70-44bf-ae14-90c7946422d7^cncChannel=GET /installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config HTTP/1.1::~~Accept-Language: en-XX::~~User-Agent: DownloadMR/1.2.4+ (MSIE 8.0;
Windows NT 5.1 SP3; DB\=ie; 9bf59659-7f5b-02eb-8c69-ce6a8ca6b231; m\=wXuH; u\=admin; aurora)::~~Host:
49939.northstar.api.socdn.com::~~Connection: Keep-Alive::~~::~~^

riskware-infection (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|riskware-callback|devTime=Jun 29 2020 07:49:43 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=xx.x.x.xx^dst=xxx.xx.xxx.x^srcPort=1072^dstPort=80^srcMAC=00:20:18:11:01:43^dstMAC=00:01:
6c:a9:2f:27^url=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config^link=https://abc.mrl.trellix.com/detection/objects?uuid=36e8bce0-1f70-44bf-ae14-
90c7946422d7^vlan=0^externalId=380^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.MultiPlug^dvc=10.5.
6.16^uuid=36e8bce0-1f70-44bf-ae14-90c7946422d7^cncChannel=GET /installer/ad0d8641-dff0-11e3-8a58-
80c16e6f498c/12932238/config HTTP/1.1::~~Accept-Language: en-XX::~~User-Agent: DownloadMR/1.2.4+ (MSIE 8.0;
Windows NT 5.1 SP3; DB\=ie; 9bf59659-7f5b-02eb-8c69-ce6a8ca6b231; m\=wXuH; u\=admin; aurora)::~~Host:
49939.northstar.api.socdn.com::~~Connection: Keep-Alive::~~::~~^ .

riskware-object (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916090|riskware-object|devTime=Jun 26 2020 12:30:41 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss z^sev=1^link=https://abc.mrl.trellix.com/detection/objects?uuid=3a523bed-b7d4-4d80-b236-
f0cd3b1b811e^vlan=0^externalId=2483^dvchost=abc.mrl.trellix.com^action=blocked^sname=CustomPolicy.MVX.65003.Exe
cutableDeliveredByEmail.^fileHash=41a0d67ba3833d230f1229ff058be057^filePath=Microsoft_
Corporation.dll^osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112^dvc=10.5.6.174^duser=brownie@tesoro.com^suser=brownie@tesoro.com^msg=3b670a25-15b6-134f-02b3-
d5745ab7722f@tesoro.com^uuid=3a523bed-b7d4-4d80-b236-
f0cd3b1b811e^sha256sum=4f11443a2fa6c714d3e33597f0d08de4e11a6a2fdb7de2e4a01addd5977665c5^subject=Riskware
Object^

riskware-callback (IPv4) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-callback|devTime=Oct 22 2020 08:49:09 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=xx.x.x.xx^dst=xxx.xx.xxx.x^srcPort=1076^dstPort=80^srcMAC=00:20:18:11:01:43^dstMAC=00:01:
6c:a9:2f:27^url=http://stan.mxp533.com/__dmp__
/^link=https://abc.mrl.trellix.com/detection/objects?uuid=9684f196-ec61-4d08-9866-
7f23db30c6db^vlan=0^externalId=120^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.SoftPulse^dvc=xx.x.
x.xxx^uuid=9684f196-ec61-4d08-9866-7f23db30c6db^cncChannel=POST /__dmp__/ HTTP/1.1::~~User-Agent: dBrowser 1
CallGetResponse:1::~~Host: stan.mxp533.com::~~Content-Length: 237::~~Cache-Control: no-cache::~~::~~data\=
{"msg":"Connection failed","url":"","lno":0,"xtra":"","method":"function getResponseFromWrapper
(url,post,callback,failcallback){window.external.getResponse
(url,post,callback,failcallback)}","version":"1.5.7","av":"","fw":"","as":""}^ .

riskware-callback (IPv6) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-callback|devTime=Oct 22 2020 09:15:57 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^proto=tcp^src=2011::1:67e7:bf08^dst=2011::1:3c33:39f1^srcPort=1072^dstPort=80^srcMAC=00:20:18:11:01:43^
dstMAC=00:01:6c:a9:2f:27^url=http://savepop.co.kr/app/download/partner/2/savepop_
agent.exe^link=https://abc.mrl.trellix.com/detection/objects?uuid=0b623598-7795-4ca1-a1a1-
9f2b02ae880b^vlan=0^externalId=771^dvchost=abc.mrl.trellix.com^action=notified^sname=Adware.AppCare.Savepop^dvc
=xx.x.x.xxx^uuid=0b623598-7795-4ca1-a1a1-9f2b02ae880b^cncChannel=GET /app/download/partner/2/savepop_agent.exe
HTTP/1.0::~~Host: savepop.co.kr::~~User-Agent: NSISDL/1.2 (Mozilla)::~~Accept: */*::~~::~~^ .

riskware-infection (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.924861|riskware-infection|devTime=Oct 16 2020 14:08:36 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^src=xx.xxx.xxx.xxx^dst=xx.xx.xx.xx^srcPort=50748^dstPort=80^srcMAC=00:50:56:b4:67:9b^dstMAC=a0:d3:c1:f1
:4a:7d^url=172.16.1.2/~kjohnson/CVE-2014-
8439/Exploit.html^link=https://abc.mrl.trellix.com/detection/objects?uuid=ed14f6a4-9796-4dec-9602-
f6ce7cec871f^vlan=0^externalId=4077^dvchost=abc.mrl.trellix.com^action=notified^sname=PUP.Generic.MVX^osinfo=Mi
crosoft Windows7 32-bit 6.1 sp1 17.0114^dvc=xx.x.x.xxx^uuid=ed14f6a4-9796-4dec-9602-f6ce7cec871f^ .

riskware-object (IPv4) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-object|devTime=Oct 22 2020 09:16:39 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^src=xx.xx.xx.xx^dst=xx.xx.xx.xx^srcPort=55059^dstPort=80^srcMAC=10:60:4b:a9:b4:04^dstMAC=10:60:4b:a9:86
:18^url=15.15.15.11/YaraAdware^link=https://abc.mrl.trellix.com/detection/objects?uuid=bdab4b33-6856-40ec-93be-
1b4d7cd5968d^vlan=0^externalId=151^dvchost=abc.mrl.trellix.com^action=notified^sname=FE_Adware_
00fc8020ad243161^fileHash=a5a4de61293d9dba3a46ec7e67f07c30^filePath=YaraAdware^dvc=xx.x.x.xxx^uuid=bdab4b33-
6856-40ec-93be-1b4d7cd5968d^sha256sum=25b8e3cc4774975876c36de3a6e5a34bb7a48857e4f02c36416aed7631d03094^protoheader=
GET /YaraAdware HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host:
15.15.15.11::~~Connection: Keep-Alive::~~HTTP/1.1 200 OK::~~Date: Mon, 12 Oct 2015 17:14:02 GMT::~~Server:
Apache/2.2.15 (CentOS)::~~Last-Modified: Wed, 30 Sep 2015 19:59:50 GMT::~~ETag: "194077b-ba988-
520fc5f8cfd9d"::~~Accept-Ranges: bytes::~~Content-Length: 764296::~~Connection: close::~~Content-Type:
text/plain; charset\=UTF-8::~~^ .

riskware-object (IPv6) (Network Security)

LEEF:1.0|Trellix|MPS|9.0.2.925495|riskware-object|devTime=Oct 22 2020 09:43:47 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss
z^sev=1^src=2011::1:4d84:9b6e^dst=2011::1:13f5:7d67^srcPort=50998^dstPort=80^srcMAC=d8:9d:67:17:19:71^dstMAC=d8
:9d:67:17:24:75^url=xx.x.x.xx/30dbe64027e570ada595c1e7b89664db.zip^link=https://abc.mrl.trellix.com/detection/o
bjects?uuid=68119bb0-bf35-4124-9af3-
13c27c7ebdaa^vlan=0^externalId=224^dvchost=abc.mrl.trellix.com^action=notified^sname=FE_Adware_
Searchbar^fileHash=904478b16474f63737389b8244a66dca^filePath=30dbe64027e570ada595c1e7b89664db.zip^dvc=xx.x.x.xx
x^uuid=68119bb0-bf35-4124-9af3-
13c27c7ebdaa^sha256sum=ea74197e0337a03dd6c2565d37d37dec2e0595747b99db3f4094a686f06ef390^proto-header=GET
/30dbe64027e570ada595c1e7b89664db.zip HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host:
xx.x.x.xx::~~Connection: Keep-Alive::~~HTTP/1.1 200 OK::~~Date: Wed, 14 Oct 2015 17:52:23 GMT::~~Server:
Apache/2.2.15 (CentOS)::~~Last-Modified: Wed, 14 Oct 2015 17:50:19 GMT::~~ETag: "380415-43c3-
52214321e1b2a"::~~Accept-Ranges: bytes::~~Content-Length: 1^ .

riskware-object (Email Security)

LEEF:1.0|Trellix|eMPS|9.0.2.925255|riskware-object|devTime=Oct 22 2020 10:09:29 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss z^sev=1^link=https://abc-123.mrl.trellix.com/detection/objects?uuid=8c145d59-3b5e-4bab-b628-
f88476ba092c^vlan=0^externalId=29^dvchost=abc-
123.mrl.trellix.com^action=blocked^sname=Adware.FileTour^fileHash=23780117a00b9b3526c3a0a3ea7c590f^filePath=Bot
tCom_riskware1.exe^osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0114^dvc=xx.x.x.xxx^duser=samples@tesoro.com^suser=sample@tesoro.com^msg=33fe63a5-eba7-8bb4-98fa-
31b41cc38d25@tesoro.com^uuid=8c145d59-3b5e-4bab-b628-
f88476ba092c^sha256sum=c78be5b7b2bcb2c69ae2c1d161a2f89710638f852ddabbce0f8f675272d559e4^subject=Riskware
blocked :: original^cncChannel=GET /php/track1.php HTTP/1.0::~~Host: soft.freemusicdownloads.world::~~User-
Agent: InnoTools_Downloader::~~::~~^ .

SmartVision (Network Security)

LEEF:1.0|Trellix|MPS|9.0.0.916432|smartvision-event|^devTime=Jun 26 2020 12:42:06 UTC^devTimeFormat=MMM dd yyyy
HH:mm:ss z^externalId=1^action=notified^sid=91500000^sigrevision=5^sev=5^uuid=20281250-7c27-4cce-a410-
2f04e1002c6e^name=Suspicious Remote Scheduled Task Activity^cat=T1053 / Remote Execution^msg=Suspicious Remote
Scheduled Task
Activity^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^link=https://abc.mrl.trellix.com/notificatio
n_url?uuid\=20281250-7c27-4cce-a410-2f04e1002c6e^ LEEF:1.0|Trellix|MPS|9.0.0.916432|smartvision-baseevent|^
devTime=Jun 26 2020 12:42:07 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss z^eventId=1^alertId=1^name=SMB
Create Request: Delete file in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|s
martvision-base-event|^devTime=Jun 26 2020 12:42:06 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=2^alertId=1^name=SMB Create Request: File in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|smartvision-base-event|^devTime=Jun 26 2020 12:42:07
UTC^devTimeFormat=MMM dd yyyy HH:mm:ss z^eventId=3^alertId=1^name=ATSVC Start
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|s
martvision-base-event|^devTime=Jun 26 2020 12:42:07 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=4^alertId=1^name=ATSVC Delete
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|MPS|9.0.0.916432|s
martvision-base-event|^devTime=Jun 26 2020 12:42:06 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=5^alertId=1^name=ATSVC Add Job: cmd.exe /C with
redirect^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA

SmartVision (Network Security on Central Management)

LEEF:1.0|Trellix|CMS|9.0.0.916210|smartvision-base-event|^devTime=Jun 29 2020 08:13:34 UTC^devTimeFormat=MMM dd
yyyy HH:mm:ss z^eventId=12^alertId=7^name=ATSVC Add Job: cmd.exe /C with
redirect^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|smartvision-base-event|^devTime=Jun 29 2020 08:13:35
UTC^devTimeFormat=MMM dd yyyy HH:mm:ss z^eventId=14^alertId=7^name=ATSVC Start
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|s
martvision-base-event|^devTime=Jun 29 2020 08:13:35 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=15^alertId=7^name=ATSVC Delete
Job^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|s
martvision-base-event|^devTime=Jun 29 2020 08:13:35 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=11^alertId=7^name=SMB Create Request: Delete file in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"user":
"DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|s
martvision-base-event|^devTime=Jun 29 2020 08:13:34 UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^eventId=13^alertId=7^name=SMB Create Request: File in Windows temp
direcory^proto=tcp^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^sev=1^eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA^LEEF:1.0|Trellix|CMS|9.0.0.916210|smartvision-event|^devTime=Jun 29 2020 08:13:34
UTC^devTimeFormat=MMM dd yyyy HH:mm:ss
z^externalId=7^action=notified^sid=91500000^sigrevision=5^sev=5^uuid=5985dbd8-5066-4e04-b560-
3f05c93506d6^name=Suspicious Remote Scheduled Task Activity^cat=T1053 / Remote Execution^msg=Suspicious Remote
Scheduled Task
Activity^src=xxx.xxx.x.x^dst=xxx.xxx.x.x^srcPort=43520^dstPort=445^link=https://abc.mrl.trellix.com/notificatio
n_url?uuid\=5985dbd8-5066-4e04-b560-3f05c93506d6^