Wazuh notification - wsrv01 - Alert level 12
Wazuh Notification. 2026 Aug 19 18:25:41 Received From: wsrv01->3.127.141.35 Rule: 65708 fired (level 12) -> "Cylance: Multiple malware events have been detected on cb-403" Portion of the log(s): 1 2026-08-19T16:25:40.965000+00:00 sysloghost CylancePROTECT - - - Event Type: Threat, Event Name: threat_found, Device Name: cb-403, IP Address: (192.168.1.151, 2001:1711:fa52:e6f0:1838:bb40:52a2:d24b, 2001:1711:fa52:e6f0:d84c:f395:56b6:a40d), File Name: fix, Path: /opt/homebrew/Cellar/go/1.26.6/libexec/pkg/tool/darwin_arm64/, Drive Type: Internal Hard Drive, SHA256: F3A47F5529451BAA3589E2CF778CB84F5A3F67CC4819F77E86A1DA4E2D6CE709, MD5: 99468CFF0152CF86AF3109C3E54746BB, Status: Default, Cylance Score: 100, Found Date: 8/19/2026 4:25:09 PM, File Type: MacOSExe, Is Running: False, Auto Run: False, Detected By: BackgroundThreatDetection, Zone Names: (Core-IT Mac), Is Malware: False, Is Unique To Cylance: True, Threat Classification: PUP - Generic, Device Id: 1f2616b8-37aa-4580-90dc-d50ad8a592fd, Policy Name: Core-IT - Protection mode CylancePROTECT.Event.Type: Threat CylancePROTECT.Event.Name: threat_found CylancePROTECT.Device.Name: cb-403 CylancePROTECT.IP.Address: 192.168.1.151 CylancePROTECT.Device.ID: 1f2616b8-37aa-4580-90dc-d50ad8a592fd CylancePROTECT.Policy.Name: Core-IT - Protection mode CylancePROTECT.File.Name: fix CylancePROTECT.File.Path: /opt/homebrew/Cellar/go/1.26.6/libexec/pkg/tool/darwin_arm64/ CylancePROTECT.Drive.Type: Internal Hard Drive CylancePROTECT.SHA265: F3A47F5529451BAA3589E2CF778CB84F5A3F67CC4819F77E86A1DA4E2D6CE709 CylancePROTECT.MD5: 99468CFF0152CF86AF3109C3E54746BB CylancePROTECT.Status: Default CylancePROTECT.Cylance.Score: 100 CylancePROTECT.Found.Date: 8/19/2026 4:25:09 PM CylancePROTECT.File.Type: MacOSExe CylancePROTECT.Is.Running: False CylancePROTECT.Auto.Run: False CylancePROTECT.Detected.By: BackgroundThreatDetection CylancePROTECT.Is.Malware: False CylancePROTECT.Is.Unique.To.Cylance: True CylancePROTECT.Threat.Classification: PUP 1 2026-08-19T16:25:40.921000+00:00 sysloghost CylancePROTECT - - - Event Type: Threat, Event Name: threat_found, Device Name: cb-403, IP Address: (192.168.1.151, 2001:1711:fa52:e6f0:1838:bb40:52a2:d24b, 2001:1711:fa52:e6f0:d84c:f395:56b6:a40d), File Name: cover, Path: /opt/homebrew/Cellar/go/1.26.6/libexec/pkg/tool/darwin_arm64/, Drive Type: Internal Hard Drive, SHA256: D87E195ED03C758850F151F0124BA85E5087EF747FE0E575AAEBD0CB6A20C2DD, MD5: 25A7C97899B2E6038F80F643E41298A2, Status: Suspicious, Cylance Score: 30, Found Date: 8/19/2026 4:25:09 PM, File Type: MacOSExe, Is Running: False, Auto Run: False, Detected By: BackgroundThreatDetection, Zone Names: (Core-IT Mac), Is Malware: False, Is Unique To Cylance: True, Threat Classification: PUP - Generic, Device Id: 1f2616b8-37aa-4580-90dc-d50ad8a592fd, Policy Name: Core-IT - Protection mode 1 2026-08-19T16:25:40.878000+00:00 sysloghost CylancePROTECT - - - Event Type: Threat, Event Name: threat_found, Device Name: cb-403, IP Address: (192.168.1.151, 2001:1711:fa52:e6f0:1838:bb40:52a2:d24b, 2001:1711:fa52:e6f0:d84c:f395:56b6:a40d), File Name: gofmt, Path: /opt/homebrew/Cellar/go/1.26.6/libexec/bin/, Drive Type: Internal Hard Drive, SHA256: 9DB70943BF222DD28DABF07F1BD6791250D1A8C2DEBF1F17F3A022CD431132B2, MD5: 3B00D6EEB167790E089AF5B3DB7839FB, Status: Suspicious, Cylance Score: 30, Found Date: 8/19/2026 4:25:09 PM, File Type: MacOSExe, Is Running: False, Auto Run: False, Detected By: BackgroundThreatDetection, Zone Names: (Core-IT Mac), Is Malware: False, Is Unique To Cylance: True, Threat Classification: PUP - Generic, Device Id: 1f2616b8-37aa-4580-90dc-d50ad8a592fd, Policy Name: Core-IT - Protection mode 1 2026-08-19T16:25:40.836000+00:00 sysloghost CylancePROTECT - - - Event Type: Threat, Event Name: threat_found, Device Name: cb-403, IP Address: (192.168.1.151, 2001:1711:fa52:e6f0:1838:bb40:52a2:d24b, 2001:1711:fa52:e6f0:d84c:f395:56b6:a40d), File Name: preprofile, Path: /opt/homebrew/Cellar/go/1.26.6/libexec/pkg/tool/darwin_arm64/, Drive Type: Internal Hard Drive, SHA256: 62913330ADDEDA14D3E3C92261BD95943EF4264215C7E31602EC1A364C0D5BA0, MD5: 68B4BA09685D07CF1AF100D1811EB16F, Status: Suspicious, Cylance Score: 30, Found Date: 8/19/2026 4:25:09 PM, File Type: MacOSExe, Is Running: False, Auto Run: False, Detected By: BackgroundThreatDetection, Zone Names: (Core-IT Mac), Is Malware: False, Is Unique To Cylance: True, Threat Classification: PUP - Generic, Device Id: 1f2616b8-37aa-4580-90dc-d50ad8a592fd, Policy Name: Core-IT - Protection mode 1 2026-08-19T16:25:40.788000+00:00 sysloghost CylancePROTECT - - - Event Type: Threat, Event Name: threat_found, Device Name: cb-403, IP Address: (192.168.1.151, 2001:1711:fa52:e6f0:1838:bb40:52a2:d24b, 2001:1711:fa52:e6f0:d84c:f395:56b6:a40d), File Name: link, Path: /opt/homebrew/Cellar/go/1.26.6/libexec/pkg/tool/darwin_arm64/, Drive Type: Internal Hard Drive, SHA256: 416856F565F03AC96190BDADB3B4549498175A401199F446ACF5CED1DC911CE1, MD5: 0449598208774B89B4EF4AFBDF50F014, Status: Default, Cylance Score: 100, Found Date: 8/19/2026 4:25:09 PM, File Type: MacOSExe, Is Running: False, Auto Run: False, Detected By: BackgroundThreatDetection, Zone Names: (Core-IT Mac), Is Malware: False, Is Unique To Cylance: True, Threat Classification: PUP - Generic, Device Id: 1f2616b8-37aa-4580-90dc-d50ad8a592fd, Policy Name: Core-IT - Protection mode --END OF NOTIFICATION
participants (1)
-
Wazuh