ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1571
Non-Standard Port
CampaignC0032

During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2.

T1571
Non-Standard Port
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008.

T1571
Non-Standard Port
CampaignOperation Wocao

During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000.

T1571
Non-Standard Port
CampaignQuad7 Activity

Quad7 Activity has used non-standard TCP ports – such as 7777, 11288, 63256, 63210, 3256, and 3556 for C2.

T1571
Non-Standard Port
GroupAPT32

An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration.

T1571
Non-Standard Port
GroupMuddyWater

MuddyWater has used ports 8043 and 8848 for botnet C2 communication.

T1571
Non-Standard Port
GroupRedEcho

RedEcho has used non-standard ports such as TCP 8080 for HTTP communication.

T1571
Non-Standard Port
GroupGamaredon Group

Gamaredon Group has used port 6856 for C2 communications.

T1571
Non-Standard Port
GroupFIN7

FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules.

T1571
Non-Standard Port
GroupSandworm Team

Sandworm Team has used port 6789 to accept connections on the group's SSH server.

T1571
Non-Standard Port
GroupRocke

Rocke's miner connects to a C2 server using port 51640.

T1571
Non-Standard Port
GroupContagious Interview

Contagious Interview has used TCP port 1224 for C2.

T1571
Non-Standard Port
GroupDarkVishnya

DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2.

T1571
Non-Standard Port
GroupEmber Bear

Ember Bear has used various non-standard ports for C2 communication.

T1571
Non-Standard Port
GroupAPT-C-36

APT-C-36 has used port 4050 for C2 communications.

T1571
Non-Standard Port
GroupLazarus Group

Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches.

T1571
Non-Standard Port
GroupSilence

Silence has used port 444 when sending data about the system from the client to the server.

T1571
Non-Standard Port
GroupVelvet Ant

Velvet Ant has used random high number ports for PlugX listeners on victim devices.

T1571
Non-Standard Port
GroupWIRTE

WIRTE has used HTTPS over ports 2083 and 2087 for C2.

T1571
Non-Standard Port
GroupMagic Hound

Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP.

T1571
Non-Standard Port
GroupAPT33

APT33 has used HTTP over TCP ports 808 and 880 for command and control.

T1571
Non-Standard Port
MalwareTrickBot

Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443.

T1571
Non-Standard Port
MalwarePikabot

Pikabot uses non-standard ports, such as 2967, 2223, and others, for HTTPS command and control communication.

T1571
Non-Standard Port
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol over TCP port 443.

T1571
Non-Standard Port
MalwareSardonic

Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443.

T1571
Non-Standard Port
MalwareRedLeaves

RedLeaves can use HTTP over non-standard ports, such as 995, for C2.

T1571
Non-Standard Port
MalwareGravityRAT

GravityRAT has used HTTP over a non-standard port, such as TCP port 46769.

T1571
Non-Standard Port
MalwareInvisibleFerret

InvisibleFerret has been observed utilizing HTTP communications to the C2 server over ports 1224, 2245 and 8637.

T1571
Non-Standard Port
MalwareBankshot

Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method.

T1571
Non-Standard Port
MalwareStrongPity

StrongPity has used HTTPS over port 1402 in C2 communication.

T1571
Non-Standard Port
MalwareHannotog

Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes.

T1571
Non-Standard Port
MalwareEmotet

Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S.

T1571
Non-Standard Port
MalwareSystemBC

The server component of SystemBC has used various TCP ports for C2 communication.

T1571
Non-Standard Port
MalwarePingPull

PingPull can use HTTPS over port 8080 for C2.

T1571
Non-Standard Port
MalwareSUGARUSH

SUGARUSH has used port 4585 for a TCP connection to its C2.

T1571
Non-Standard Port
MalwareHOPLIGHT

HOPLIGHT has connected outbound over TCP port 443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareRaspberry Robin

Raspberry Robin will communicate via HTTP over port 8080 for command and control traffic.

T1571
Non-Standard Port
MalwareBeaverTail

BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244.

T1571
Non-Standard Port
MalwarePlugX

PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities.

T1571
Non-Standard Port
MalwareTYPEFRAME

TYPEFRAME has used ports 443, 8080, and 8443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareVIRTUALPIE

VIRTUALPIE has created listeners on hard coded TCP port 546.

T1571
Non-Standard Port
MalwareBendyBear

BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2.

T1571
Non-Standard Port
MalwareGlassWorm

GlassWorm has distributed C2 using BitTorrent’s Distributed Hash Table (DHT) network to harness a decentralized command capability.

T1571
Non-Standard Port
MalwareMetamorfo

Metamorfo has communicated with hosts over raw TCP on port 9999.

T1571
Non-Standard Port
MalwareRTM

RTM used Port 44443 for its VNC module.

T1571
Non-Standard Port
MalwareDerusbi

Derusbi has used unencrypted HTTP on port 443 for C2.

T1571
Non-Standard Port
MalwareWellMail

WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications.

T1571
Non-Standard Port
MalwareBADCALL

BADCALL communicates on ports 443 and 8000 with a FakeTLS method.

T1571
Non-Standard Port
MalwareMoonWind

MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports.

T1571
Non-Standard Port
MalwareHiddenFace

HiddenFace's passive mode listens on TCP 47000.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.