Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)

Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.

FreeReviewedSigma · High · v2
Product
windows
Category
network_connection
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-03-19
Updated
2026-07-31
title: Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
id: 9f8481e2-9829-4f64-9ab5-3feed85d59cb
related:
  - id: 6d8c3d20-a5e1-494f-8412-4571d716cf5c
    type: similar
  - id: 4b89abaa-99fe-4232-afdd-8f9aa4d20382
    type: derived
status: test
description: This rule flags Windows processes that initiate network connections to a list of destination ports commonly associated with malware callback traffic. Such activity can indicate command-and-control behavior where malware establishes outbound connectivity to external infrastructure. It relies on network connection telemetry capturing whether the connection was initiated and the destination IP and port, with exclusions for local and private ranges and common program directories.
references:
  - https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_susp_malware_callback_port.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-19
modified: 2024-03-12
tags:
  - attack.persistence
  - attack.command-and-control
  - attack.t1571
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    Initiated: "true"
    DestinationPort:
      - 100
      - 198
      - 200
      - 243
      - 473
      - 666
      - 700
      - 743
      - 777
      - 1443
      - 1515
      - 1777
      - 1817
      - 1904
      - 1960
      - 2443
      - 2448
      - 3360
      - 3675
      - 3939
      - 4040
      - 4433
      - 4438
      - 4443
      - 4444
      - 4455
      - 5445
      - 5552
      - 5649
      - 6625
      - 7210
      - 7777
      - 8143
      - 8843
      - 9631
      - 9943
      - 10101
      - 12102
      - 12103
      - 12322
      - 13145
      - 13394
      - 13504
      - 13505
      - 13506
      - 13507
      - 14102
      - 14103
      - 14154
      - 49180
      - 65520
      - 65535
  filter_main_local_ranges:
    DestinationIp|cidr:
      - 127.0.0.0/8
      - 10.0.0.0/8
      - 172.16.0.0/12
      - 192.168.0.0/16
      - 169.254.0.0/16
      - ::1/128
      - fe80::/10
      - fc00::/7
  filter_optional_sys_directories:
    Image|startswith:
      - C:\Program Files\
      - C:\Program Files (x86)\
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1