The infected computer (or Bot server) is redirected to an exploit site from which malware is downloaded to be centrally controlled by the CnC.
Callback activity (botnet server) alerts are generated when the Email Security appliance detects outbound communication associated with a remote CnC server, indicating that there is an established connection between an infected host (bot) and the CnC server. Communication include malware command and control communication, and uploads of confidential information, as well as downloads of secondary payloads (such as keyloggers or spyware).
The Email Security - Server appliance generates malware object alerts and riskware alerts and are reported as events displayed in the Web UI and CLI as:
Bot Communication Details—Servers, ports, and commands.
Callback communication observed from VM—Responses from the infected host.
The following list shows some of the details that are displayed:
Server DNS Name
Service Port
Last Seen at (date/time)
Signature Name
Direction
Command
User-Agent
Host Connection