Potentially Suspicious Malware Callback Communication

 Original Source: [Sigma source]
Title: Potentially Suspicious Malware Callback Communication
Status: test
Description:Detects programs that connect to known malware callback ports based on statistical analysis from two different sandbox system databases
References:
  -https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo
Author: Florian Roth (Nextron Systems)
Date: 2017-03-19
modified:2024-03-12
Tags:
  • -'attack.persistence'
  • -'attack.command-and-control'
  • -'attack.t1571'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    Initiated: 'true'
    DestinationPort:
      -'100'
      -'198'
      -'200'
      -'243'
      -'473'
      -'666'
      -'700'
      -'743'
      -'777'
      -'1443'
      -'1515'
      -'1777'
      -'1817'
      -'1904'
      -'1960'
      -'2443'
      -'2448'
      -'3360'
      -'3675'
      -'3939'
      -'4040'
      -'4433'
      -'4438'
      -'4443'
      -'4444'
      -'4455'
      -'5445'
      -'5552'
      -'5649'
      -'6625'
      -'7210'
      -'7777'
      -'8143'
      -'8843'
      -'9631'
      -'9943'
      -'10101'
      -'12102'
      -'12103'
      -'12322'
      -'13145'
      -'13394'
      -'13504'
      -'13505'
      -'13506'
      -'13507'
      -'14102'
      -'14103'
      -'14154'
      -'49180'
      -'65520'
      -'65535'

  filter_main_local_ranges:
    DestinationIp|cidr:
      -'127.0.0.0/8'
      -'10.0.0.0/8'
      -'172.16.0.0/12'
      -'192.168.0.0/16'
      -'169.254.0.0/16'
      -'::1/128'
      -'fe80::/10'
      -'fc00::/7'

  filter_optional_sys_directories:
    Image|startswith:
      -'C:\Program Files\'
      -'C:\Program Files (x86)\'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: high