The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alerts grouped by CnC servers contacted

Prev Next

This topic covers the following information:

  • About the callback activity page

  • Fields in the callback activity list

  • Details for a CnC server-specific alert grouping

Note

The Callback Activity page does not contain information about IPS events or IPS alerts. For more detailed information about the Callback Activity page, see the Network Security User Guide.

About the callback activity page

An IPS platform offers three views of malware events. Two views list malware alerts (both MVX-verified malware events and MVX-correlated IPS events), and the third view lists callback activity associated with malware. When you choose Alerts > Alerts, the Hosts tab is selected by default.

To view the alerts grouped by command and control (CnC) server, click the Callback Activity link in the control bar:

Note

The Callback Activity page does not display IPS information.

The Callback Activity view of the alerts lists all CnC servers contacted by infected hosts. Multiple callback to the same CnC server are combined in a single entry in the list.

Fields in the callback activity list

Each row of results in the Callback Activity list displays the following information about a suspicious callback event:

Column

Description

ctrl_ips_drill-down_ips.png

Click to expand the row to display additional results.

C&C Server

Host name or IP address of the botnet CnC server that directs the callback activity.

Location

Geographical location of the botnet CnC server, if known. This information appears only if geo-location data is loaded.

Events

Number of callback events seen for this CnC server.

Hosts

Number of hosts on the monitored network that have been verified as botnet zombies under the control of the CnC server.

Last Seen at

Date and time the most recent callback event. Times are displayed in UTC format by default. To set the time zone, choose Settings > Date and Time.

Details for a CnC server-specific alert grouping

Click the gold triangle to expand an entry in the Callback Activity tab. The drill-down view displays the following information about the callback event. For more information, see the Network Security User Guide.

Field

Description

Service Port(s)

System port number used by the malware to connect to the CnC server.

IP Protocol(s)

Types of IP traffic for which a FireEye CnC rule matched traffic: TCP, UDP, or HTTP.

First Seen

Date and time when the callback activity was first detected (within the period of time displayed in the Hosts tab and the Alerts tab).

VM‑verified Hosts

Number of infected hosts that initiated MVX-verified outbound communication with a CnC server associated with the callback event. If the value is nonzero, this field is followed by the list of infected hosts.

ipAddress

(

count

)

Example of a single host IP address and callback count: scap_ips_callback_activity_drilldown_ip_and_count.png

ipAddress

—In the example, 10.189.183.252 is the IP address of an infected host that attempted to contact the CnC server. Click the IP address to open the Hosts tab. The list is filtered on the Host column for the IP address of the infected host, and each retrieved entry is expanded to show the malware detected for that host.

count

—In the example, is the number of MVX-verified callback attempts by the infected host is shown enclosed in parentheses. Click the number to open the Hosts tab. The list is filtered as follows:

• Source IP= IP address of the infected host

• Target IP= IP address of the CnC server

Callback Hosts

Number of infected hosts that initiated outbound communication with a CnC server associated with the callback event. If the value is nonzero, this field is followed by the list of infected hosts.

ipAddress

(

count

)

Example of a single host IP address and callback count: scap_ips_callback_activity_drilldown_ip_and_count.png

ipAddress

—In the example, 10.189.183.252 is the IP address of an infected host that attempted to contact the CnC server. Click the IP address to open the Hosts tab. The list is filtered on the Host column for the IP address of the infected host, and each retrieved entry is expanded to show the malware detected for that host.

count

—In the example, is the number of callback attempts by the infected host is shown enclosed in parentheses. Click the number to open the Hosts tab. The list is filtered as follows:

• Source IP= IP address of the infected host

• Target IP= IP address of the CnC server