Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1571 Non-Standard Port |
GroupAPT32 | An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration. |
| T1571 Non-Standard Port |
GroupMuddyWater | MuddyWater has used ports 8043 and 8848 for botnet C2 communication. |
| T1571 Non-Standard Port |
GroupRedEcho | RedEcho has used non-standard ports such as TCP 8080 for HTTP communication. |
| T1571 Non-Standard Port |
GroupGamaredon Group | Gamaredon Group has used port 6856 for C2 communications. |
| T1571 Non-Standard Port |
GroupFIN7 | FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules. |
| T1571 Non-Standard Port |
GroupSandworm Team | Sandworm Team has used port 6789 to accept connections on the group's SSH server. |
| T1571 Non-Standard Port |
GroupRocke | Rocke's miner connects to a C2 server using port 51640. |
| T1571 Non-Standard Port |
GroupContagious Interview | Contagious Interview has used TCP port 1224 for C2. |
| T1571 Non-Standard Port |
GroupDarkVishnya | DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2. |
| T1571 Non-Standard Port |
GroupEmber Bear | Ember Bear has used various non-standard ports for C2 communication. |
| T1571 Non-Standard Port |
GroupAPT-C-36 | APT-C-36 has used port 4050 for C2 communications. |
| T1571 Non-Standard Port |
GroupLazarus Group | Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches. |
| T1571 Non-Standard Port |
GroupSilence | Silence has used port 444 when sending data about the system from the client to the server. |
| T1571 Non-Standard Port |
GroupVelvet Ant | Velvet Ant has used random high number ports for PlugX listeners on victim devices. |
| T1571 Non-Standard Port |
GroupWIRTE | WIRTE has used HTTPS over ports 2083 and 2087 for C2. |
| T1571 Non-Standard Port |
GroupMagic Hound | Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP. |
| T1571 Non-Standard Port |
GroupAPT33 | APT33 has used HTTP over TCP ports 808 and 880 for command and control. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.