The Network page is split into three sections: Callbacks, Network Anomalies, and Network Events.
A network callback is sent by a threat to collect data and control a system remotely.
A network anomaly is a sudden, but short-lived, change from the expected operation of the network. This may indicate that your system has been infected with malware.
The following table describes the information on the Callbacks and Network Anomalies section:
Column | Description |
|---|---|
Port | The port number of the network process. |
DNS Name | The Domain Name System name. |
Payload | The data embedded in the network call. |
Signature Name | The name of the threat group behind a malicious attack. |
Weight | The score assigned to the signature. If the score is greater than or equal to 100, the sample is malicious. |
The following table describes the information on the Network Events section:
Column | Description |
|---|---|
Mode | The type of network event, such as DNS query, listen, and so on. |
Host Name | IP address or host name of the destination. |
Protocol | The type of network event. |
Process Name | The name of the process accessed by the sample. |
PID | The unique number assigned to identify the process. |