  • IRC traffic (botnets and bot masters use IRC for communications)

  • Connection attempts with known C&C servers

  • Multiple machines on a network making identical DNS requests

  • High outgoing SMTP traffic (as a result of sending spam)

  • Unexpected popups (as a result of clickfraud activity)

  • Slow computing/high CPU usage

  • Spikes in traffic, especially Port 6667 (used for IRC), Port 25 (used in email spamming), and Port 1080 (used by proxy servers)

  • Outbound messages (email, social media, instant messages, etc) that weren’t sent by the user

  • Problems with Internet access

