Windows Network Connections to Known Malware Callback Ports

Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.

FreeUnreviewedSigmahighv1
title: Windows Network Connections to Known Malware Callback Ports
id: 9f8481e2-9829-4f64-9ab5-3feed85d59cb
related:
  - id: 6d8c3d20-a5e1-494f-8412-4571d716cf5c
    type: similar
  - id: 4b89abaa-99fe-4232-afdd-8f9aa4d20382
    type: derived
status: test
description: This rule flags Windows processes that initiate network connections to a set of known malware callback destination ports, excluding traffic to local/private address ranges and common system program directories. Calling out these ports matters because malware frequently uses fixed listener ports for command-and-control or callback communication. The detection relies on network connection telemetry with process initiation context (Initiated) and destination port and IP, plus endpoint image path information for the optional directory exclusions.
references:
  - https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_susp_malware_callback_port.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-19
modified: 2024-03-12
tags:
  - attack.persistence
  - attack.command-and-control
  - attack.t1571
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    Initiated: "true"
    DestinationPort:
      - 100
      - 198
      - 200
      - 243
      - 473
      - 666
      - 700
      - 743
      - 777
      - 1443
      - 1515
      - 1777
      - 1817
      - 1904
      - 1960
      - 2443
      - 2448
      - 3360
      - 3675
      - 3939
      - 4040
      - 4433
      - 4438
      - 4443
      - 4444
      - 4455
      - 5445
      - 5552
      - 5649
      - 6625
      - 7210
      - 7777
      - 8143
      - 8843
      - 9631
      - 9943
      - 10101
      - 12102
      - 12103
      - 12322
      - 13145
      - 13394
      - 13504
      - 13505
      - 13506
      - 13507
      - 14102
      - 14103
      - 14154
      - 49180
      - 65520
      - 65535
  filter_main_local_ranges:
    DestinationIp|cidr:
      - 127.0.0.0/8
      - 10.0.0.0/8
      - 172.16.0.0/12
      - 192.168.0.0/16
      - 169.254.0.0/16
      - ::1/128
      - fe80::/10
      - fc00::/7
  filter_optional_sys_directories:
    Image|startswith:
      - C:\Program Files\
      - C:\Program Files (x86)\
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags Windows processes that initiate network connections to a set of known malware callback destination ports, excluding traffic to local/private address ranges and common system program directories. Calling out these ports matters because malware frequently uses fixed listener ports for command-and-control or callback communication. The detection relies on network connection telemetry with process initiation context (Initiated) and destination port and IP, plus endpoint image path information for the optional directory exclusions.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.