This topic covers the following information:
About the callback activity page
Fields in the callback activity list
Details for a CnC server-specific alert grouping
Note
The Callback Activity page does not contain information about IPS events or IPS alerts. For more detailed information about the Callback Activity page, see the Network Security User Guide.
About the callback activity page
An IPS platform offers three views of malware events. Two views list malware alerts (both MVX-verified malware events and MVX-correlated IPS events), and the third view lists callback activity associated with malware. When you choose Alerts > Alerts, the Hosts tab is selected by default.
To view the alerts grouped by command and control (CnC) server, click the Callback Activity link in the control bar:
Note
The Callback Activity page does not display IPS information.
The Callback Activity view of the alerts lists all CnC servers contacted by infected hosts. Multiple callback to the same CnC server are combined in a single entry in the list.
Fields in the callback activity list
Each row of results in the Callback Activity list displays the following information about a suspicious callback event:
Column | Description |
|---|---|
| Click to expand the row to display additional results. |
C&C Server | Host name or IP address of the botnet CnC server that directs the callback activity. |
Location | Geographical location of the botnet CnC server, if known. This information appears only if geo-location data is loaded. |
Events | Number of callback events seen for this CnC server. |
Hosts | Number of hosts on the monitored network that have been verified as botnet zombies under the control of the CnC server. |
Last Seen at | Date and time the most recent callback event. Times are displayed in UTC format by default. To set the time zone, choose Settings > Date and Time. |
Details for a CnC server-specific alert grouping
Click the gold triangle to expand an entry in the Callback Activity tab. The drill-down view displays the following information about the callback event. For more information, see the Network Security User Guide.
Field | Description |
|---|---|
Service Port(s) | System port number used by the malware to connect to the CnC server. |
IP Protocol(s) | Types of IP traffic for which a FireEye CnC rule matched traffic: TCP, UDP, or HTTP. |
First Seen | Date and time when the callback activity was first detected (within the period of time displayed in the Hosts tab and the Alerts tab). |
VM‑verified Hosts | Number of infected hosts that initiated MVX-verified outbound communication with a CnC server associated with the callback event. If the value is nonzero, this field is followed by the list of infected hosts. |
ipAddress ( count ) | Example of a single host IP address and callback count: ipAddress —In the example, 10.189.183.252 is the IP address of an infected host that attempted to contact the CnC server. Click the IP address to open the Hosts tab. The list is filtered on the Host column for the IP address of the infected host, and each retrieved entry is expanded to show the malware detected for that host. count —In the example, is the number of MVX-verified callback attempts by the infected host is shown enclosed in parentheses. Click the number to open the Hosts tab. The list is filtered as follows: • Source IP= IP address of the infected host • Target IP= IP address of the CnC server |
Callback Hosts | Number of infected hosts that initiated outbound communication with a CnC server associated with the callback event. If the value is nonzero, this field is followed by the list of infected hosts. |
ipAddress ( count ) | Example of a single host IP address and callback count: ipAddress —In the example, 10.189.183.252 is the IP address of an infected host that attempted to contact the CnC server. Click the IP address to open the Hosts tab. The list is filtered on the Host column for the IP address of the infected host, and each retrieved entry is expanded to show the malware detected for that host. count —In the example, is the number of callback attempts by the infected host is shown enclosed in parentheses. Click the number to open the Hosts tab. The list is filtered as follows: • Source IP= IP address of the infected host • Target IP= IP address of the CnC server |

