Network

Prev Next

The Network page is split into three sections: Callbacks, Network Anomalies, and Network Events.

Callbacks

A network callback is sent by a threat to collect data and control a system remotely.

Network anomalies

A network anomaly is a sudden, but short-lived, change from the expected operation of the network. This may indicate that your system has been infected with malware.

The following table describes the information on the Callbacks and Network Anomalies section:

Column

Description

Port

The port number of the network process.

DNS Name

The Domain Name System name.

Payload

The data embedded in the network call.

Signature Name

The name of the threat group behind a malicious attack.

Weight

The score assigned to the signature. If the score is greater than or equal to 100, the sample is malicious.

The following table describes the information on the Network Events section:

Column

Description

Mode

The type of network event, such as DNS query, listen, and so on.

Host Name

IP address or host name of the destination.

Protocol

The type of network event.

Process Name

The name of the process accessed by the sample.

PID

The unique number assigned to identify the process.