Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
- Product
- windows
- Category
- network_connection
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2017-03-19
- Updated
- 2026-07-31
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags Windows processes that initiate network connections to a list of destination ports commonly associated with malware callback traffic. Such activity can indicate command-and-control behavior where malware establishes outbound connectivity to external infrastructure. It relies on network connection telemetry capturing whether the connection was initiated and the destination IP and port, with exclusions for local and private ranges and common program directories.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
id: 9f8481e2-9829-4f64-9ab5-3feed85d59cb
related:
- id: 6d8c3d20-a5e1-494f-8412-4571d716cf5c
type: similar
- id: 4b89abaa-99fe-4232-afdd-8f9aa4d20382
type: derived
status: test
description: This rule flags Windows processes that initiate network connections to a list of destination ports commonly associated with malware callback traffic. Such activity can indicate command-and-control behavior where malware establishes outbound connectivity to external infrastructure. It relies on network connection telemetry capturing whether the connection was initiated and the destination IP and port, with exclusions for local and private ranges and common program directories.
references:
- https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_susp_malware_callback_port.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-19
modified: 2024-03-12
tags:
- attack.persistence
- attack.command-and-control
- attack.t1571
logsource:
category: network_connection
product: windows
detection:
selection:
Initiated: "true"
DestinationPort:
- 100
- 198
- 200
- 243
- 473
- 666
- 700
- 743
- 777
- 1443
- 1515
- 1777
- 1817
- 1904
- 1960
- 2443
- 2448
- 3360
- 3675
- 3939
- 4040
- 4433
- 4438
- 4443
- 4444
- 4455
- 5445
- 5552
- 5649
- 6625
- 7210
- 7777
- 8143
- 8843
- 9631
- 9943
- 10101
- 12102
- 12103
- 12322
- 13145
- 13394
- 13504
- 13505
- 13506
- 13507
- 14102
- 14103
- 14154
- 49180
- 65520
- 65535
filter_main_local_ranges:
DestinationIp|cidr:
- 127.0.0.0/8
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 169.254.0.0/16
- ::1/128
- fe80::/10
- fc00::/7
filter_optional_sys_directories:
Image|startswith:
- C:\Program Files\
- C:\Program Files (x86)\
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: high
license: DRL-1.1