Real-world descriptions of how a group, tool or campaign used a technique.
41 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1571 Non-Standard Port |
MalwareTrickBot | Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443. |
| T1571 Non-Standard Port |
MalwarePikabot | Pikabot uses non-standard ports, such as 2967, 2223, and others, for HTTPS command and control communication. |
| T1571 Non-Standard Port |
MalwareRotaJakiro | RotaJakiro uses a custom binary protocol over TCP port 443. |
| T1571 Non-Standard Port |
MalwareSardonic | Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443. |
| T1571 Non-Standard Port |
MalwareRedLeaves | RedLeaves can use HTTP over non-standard ports, such as 995, for C2. |
| T1571 Non-Standard Port |
MalwareGravityRAT | GravityRAT has used HTTP over a non-standard port, such as TCP port 46769. |
| T1571 Non-Standard Port |
MalwareInvisibleFerret | InvisibleFerret has been observed utilizing HTTP communications to the C2 server over ports 1224, 2245 and 8637. |
| T1571 Non-Standard Port |
MalwareBankshot | Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareStrongPity | StrongPity has used HTTPS over port 1402 in C2 communication. |
| T1571 Non-Standard Port |
MalwareHannotog | Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes. |
| T1571 Non-Standard Port |
MalwareEmotet | Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S. |
| T1571 Non-Standard Port |
MalwareSystemBC | The server component of SystemBC has used various TCP ports for C2 communication. |
| T1571 Non-Standard Port |
MalwarePingPull | PingPull can use HTTPS over port 8080 for C2. |
| T1571 Non-Standard Port |
MalwareSUGARUSH | SUGARUSH has used port 4585 for a TCP connection to its C2. |
| T1571 Non-Standard Port |
MalwareHOPLIGHT | HOPLIGHT has connected outbound over TCP port 443 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareRaspberry Robin | Raspberry Robin will communicate via HTTP over port 8080 for command and control traffic. |
| T1571 Non-Standard Port |
MalwareBeaverTail | BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244. |
| T1571 Non-Standard Port |
MalwarePlugX | PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities. |
| T1571 Non-Standard Port |
MalwareTYPEFRAME | TYPEFRAME has used ports 443, 8080, and 8443 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareVIRTUALPIE | VIRTUALPIE has created listeners on hard coded TCP port 546. |
| T1571 Non-Standard Port |
MalwareBendyBear | BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2. |
| T1571 Non-Standard Port |
MalwareGlassWorm | GlassWorm has distributed C2 using BitTorrent’s Distributed Hash Table (DHT) network to harness a decentralized command capability. |
| T1571 Non-Standard Port |
MalwareMetamorfo | Metamorfo has communicated with hosts over raw TCP on port 9999. |
| T1571 Non-Standard Port |
MalwareRTM | RTM used Port 44443 for its VNC module. |
| T1571 Non-Standard Port |
MalwareDerusbi | Derusbi has used unencrypted HTTP on port 443 for C2. |
| T1571 Non-Standard Port |
MalwareWellMail | WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications. |
| T1571 Non-Standard Port |
MalwareBADCALL | BADCALL communicates on ports 443 and 8000 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareMoonWind | MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports. |
| T1571 Non-Standard Port |
MalwareHiddenFace | HiddenFace's passive mode listens on TCP 47000. |
| T1571 Non-Standard Port |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used a custom binary protocol over TCP port 443 for C2. |
| T1571 Non-Standard Port |
MalwareCyclops Blink | Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic. |
| T1571 Non-Standard Port |
MalwareGoldenSpy | GoldenSpy has used HTTP over ports 9005 and 9006 for network traffic, 9002 for C2 requests, 33666 as a WebSocket, and 8090 to download files. |
| T1571 Non-Standard Port |
MalwareHARDRAIN | HARDRAIN binds and listens on port 443 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareMacMa | MacMa has used TCP port 5633 for C2 Communication. |
| T1571 Non-Standard Port |
MalwarePoetRAT | PoetRAT used TLS to encrypt communications over port 143 |
| T1571 Non-Standard Port |
MalwareZxShell | ZxShell can use ports 1985 and 1986 in HTTP/S communication. |
| T1571 Non-Standard Port |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has the ability to bind on a localhost and listen on port 8300. |
| T1571 Non-Standard Port |
MalwarenjRAT | njRAT has used port 1177 for HTTP C2 communications. |
| T1571 Non-Standard Port |
MalwareVIRTUALPITA | VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098. |
| T1571 Non-Standard Port |
ToolCovenant | Covenant listeners and controllers can be configured to use non-standard ports. |
| T1571 Non-Standard Port |
ToolQuasarRAT | QuasarRAT can use port 4782 on the compromised host for TCP callbacks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.