Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

[9.104-14]Threat:Mal/Iframe-AO [unusable batch line]

$
0
0
Hi

I am getting "unusable batch line" for a specific event. Log Below


Code:

2013:08:11-10:08:40 **** epsecd[5823]: I id="4211" severity="info" sys="System" sub="epsecd" name="Recieved report(s) from Sophos LiveConnect"
2013:08:11-10:08:40 **** epsecd[5823]: I id="4212" severity="info" sys="System" sub="epsecd" name="Acknowledging report(s)" reports="20161148"
2013:08:11-10:09:22 **** epsecd[5824]: W main::_log:420() => severity="warn" sys="System" sub="eplog" name="unusable batch line: [[v=1        tz=Θερινή ώρα Γκρίνουιτς        t=1375732484        cat=0        sxl=y        act=b        rsk=        rsn=v        threat=Mal/Iframe-AO        rule=        meth=        H=****-PC        h=        target_ip=        dom=www.****.com        u=****-PC\****        req= ref=www.****.com/news-events/****-648        s=0        ua=        ctype=        type=        filetype=        in=0        out=0        ]]"
2013:08:11-10:09:22 **** epsecd[5824]: W main::_log:420() => severity="warn" sys="System" sub="eplog" name="unusable batch line: [[v=1        tz=Θερινή ώρα Γκρίνουιτς        t=1375732484        cat=0        sxl=y        act=b        rsk=        rsn=v        threat=Mal/Iframe-AO        rule=        meth=        H=****-PC        h=        target_ip=        dom=www.****.com        u=****-PC\****        req= ref=www.****.com/news-events/****-648        s=0        ua=        ctype=        type=        filetype=        in=0        out=0        ]]"
2013:08:11-10:09:22 **** epsecd[5824]: W main::_log:420() => severity="warn" sys="System" sub="eplog" name="unusable batch line: [[v=1        tz=Θερινή ώρα Γκρίνουιτς        t=1375732486        cat=0        sxl=y        act=b        rsk=        rsn=v        threat=Mal/Iframe-AO        rule=        meth=        H=****-PC        h=        target_ip=        dom=www.****.com        u=****-PC\****        req= ref=www.****.com/news-events/****-648        s=0        ua=        ctype=        type=        filetype=        in=0        out=0        ]]"
2013:08:11-10:09:34 **** epsecd[5823]: I id="4211" severity="info" sys="System" sub="epsecd" name="Recieved report(s) from Sophos LiveConnect"
2013:08:11-10:09:34 **** epsecd[5823]: I id="4212" severity="info" sys="System" sub="epsecd" name="Acknowledging report(s)" reports="20161148"

Not sure what that means but the endpoint did alert me regarding this threat

thanks

Viewing all articles
Browse latest Browse all 14361

Trending Articles