Here is an example entry from the MwacDetections folder. Are they just IP addresses trying to probe me? Thanks again.
1C7D5D9BB93C6AE9DF10D3D06E2E4CFA206B951A1C3E3246E5B3A337D8616EFA
{
"applicationVersion": "5.1.7.121",
"chromeSyncResetQueryRequested": false,
"chromeSyncResetQueryResult": false,
"clientID": "",
"clientType": "other",
"componentsUpdatePackageVersion": "1.0.1293",
"coreDllFileVersion": "0.0.0",
"cpu": "x64",
"dbSDKUpdatePackageVersion": "1.0.87816",
"detectionDateTime": "2024-08-13T07:32:01Z",
"fileSystem": "NTFS",
"id": "215abee4-5946-11ef-9b95-020100024269",
"isLargePEEnabled": false,
"isUserAdmin": true,
"largePEMaxSize": 31457280,
"licenseState": "licensed",
"linkagePhaseComplete": false,
"loggedOnUserName": "System",
"machineID": "",
"os": "Windows 10 Server (Build 17763.6054)",
"schemaVersion": 22,
"sourceDetails": {
"type": "mwac"
},
"threats": [
{
"ddsSigFileVersion": "",
"linkedTraces": [
],
"mainTrace": {
"ImpersonationSid": "",
"archiveMember": "",
"archiveMemberMD5": "",
"cleanAction": "block",
"cleanResult": "successful",
"cleanResultErrorCode": 0,
"cleanTime": "",
"generatedByPostCleanupAction": false,
"hubbleRequestErrorCode": 0,
"id": "215abee5-5946-11ef-bcff-020100024269",
"igExitCode": "",
"isPEFile": false,
"isPEFileValid": false,
"isWhitelistedByAdsInfo": false,
"linkType": "none",
"objectMD5": "",
"objectPath": "System",
"objectSha256": "",
"objectSize": -1,
"objectType": "website",
"resolvedPath": "",
"rtpEventType": "other",
"websiteData": {
"blockType": 2,
"ip": "45.170.83.146",
"isInbound": true,
"netProtocol": "TCP",
"port": 445,
"processPath": "System",
"url": ""
}
},
"ruleID": -1,
"ruleString": "",
"rulesVersion": "0.0.0",
"srcEngineComponent": "unknown",
"srcEngineThreatNames": [
],
"threatID": -1,
"threatName": ""
}
],
"threatsDetected": 1
}