Windows Network Connections to Known Malware Callback Ports
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
FreeUnreviewedSigmahighv1
windows-network-connections-to-known-malware-callback-ports-4b89abaa
title: Windows Network Connections to Known Malware Callback Ports
id: 9f8481e2-9829-4f64-9ab5-3feed85d59cb
related:
- id: 6d8c3d20-a5e1-494f-8412-4571d716cf5c
type: similar
- id: 4b89abaa-99fe-4232-afdd-8f9aa4d20382
type: derived
status: test
description: This rule flags Windows processes that initiate network connections to a set of known malware callback destination ports, excluding traffic to local/private address ranges and common system program directories. Calling out these ports matters because malware frequently uses fixed listener ports for command-and-control or callback communication. The detection relies on network connection telemetry with process initiation context (Initiated) and destination port and IP, plus endpoint image path information for the optional directory exclusions.
references:
- https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_susp_malware_callback_port.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-19
modified: 2024-03-12
tags:
- attack.persistence
- attack.command-and-control
- attack.t1571
logsource:
category: network_connection
product: windows
detection:
selection:
Initiated: "true"
DestinationPort:
- 100
- 198
- 200
- 243
- 473
- 666
- 700
- 743
- 777
- 1443
- 1515
- 1777
- 1817
- 1904
- 1960
- 2443
- 2448
- 3360
- 3675
- 3939
- 4040
- 4433
- 4438
- 4443
- 4444
- 4455
- 5445
- 5552
- 5649
- 6625
- 7210
- 7777
- 8143
- 8843
- 9631
- 9943
- 10101
- 12102
- 12103
- 12322
- 13145
- 13394
- 13504
- 13505
- 13506
- 13507
- 14102
- 14103
- 14154
- 49180
- 65520
- 65535
filter_main_local_ranges:
DestinationIp|cidr:
- 127.0.0.0/8
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 169.254.0.0/16
- ::1/128
- fe80::/10
- fc00::/7
filter_optional_sys_directories:
Image|startswith:
- C:\Program Files\
- C:\Program Files (x86)\
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags Windows processes that initiate network connections to a set of known malware callback destination ports, excluding traffic to local/private address ranges and common system program directories. Calling out these ports matters because malware frequently uses fixed listener ports for command-and-control or callback communication. The detection relies on network connection telemetry with process initiation context (Initiated) and destination port and IP, plus endpoint image path information for the optional directory exclusions.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.