ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1571×

41 examples

TechniqueUsed byProcedure example
T1571
Non-Standard Port
MalwareTrickBot

Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443.

T1571
Non-Standard Port
MalwarePikabot

Pikabot uses non-standard ports, such as 2967, 2223, and others, for HTTPS command and control communication.

T1571
Non-Standard Port
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol over TCP port 443.

T1571
Non-Standard Port
MalwareSardonic

Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443.

T1571
Non-Standard Port
MalwareRedLeaves

RedLeaves can use HTTP over non-standard ports, such as 995, for C2.

T1571
Non-Standard Port
MalwareGravityRAT

GravityRAT has used HTTP over a non-standard port, such as TCP port 46769.

T1571
Non-Standard Port
MalwareInvisibleFerret

InvisibleFerret has been observed utilizing HTTP communications to the C2 server over ports 1224, 2245 and 8637.

T1571
Non-Standard Port
MalwareBankshot

Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method.

T1571
Non-Standard Port
MalwareStrongPity

StrongPity has used HTTPS over port 1402 in C2 communication.

T1571
Non-Standard Port
MalwareHannotog

Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes.

T1571
Non-Standard Port
MalwareEmotet

Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S.

T1571
Non-Standard Port
MalwareSystemBC

The server component of SystemBC has used various TCP ports for C2 communication.

T1571
Non-Standard Port
MalwarePingPull

PingPull can use HTTPS over port 8080 for C2.

T1571
Non-Standard Port
MalwareSUGARUSH

SUGARUSH has used port 4585 for a TCP connection to its C2.

T1571
Non-Standard Port
MalwareHOPLIGHT

HOPLIGHT has connected outbound over TCP port 443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareRaspberry Robin

Raspberry Robin will communicate via HTTP over port 8080 for command and control traffic.

T1571
Non-Standard Port
MalwareBeaverTail

BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244.

T1571
Non-Standard Port
MalwarePlugX

PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities.

T1571
Non-Standard Port
MalwareTYPEFRAME

TYPEFRAME has used ports 443, 8080, and 8443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareVIRTUALPIE

VIRTUALPIE has created listeners on hard coded TCP port 546.

T1571
Non-Standard Port
MalwareBendyBear

BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2.

T1571
Non-Standard Port
MalwareGlassWorm

GlassWorm has distributed C2 using BitTorrent’s Distributed Hash Table (DHT) network to harness a decentralized command capability.

T1571
Non-Standard Port
MalwareMetamorfo

Metamorfo has communicated with hosts over raw TCP on port 9999.

T1571
Non-Standard Port
MalwareRTM

RTM used Port 44443 for its VNC module.

T1571
Non-Standard Port
MalwareDerusbi

Derusbi has used unencrypted HTTP on port 443 for C2.

T1571
Non-Standard Port
MalwareWellMail

WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications.

T1571
Non-Standard Port
MalwareBADCALL

BADCALL communicates on ports 443 and 8000 with a FakeTLS method.

T1571
Non-Standard Port
MalwareMoonWind

MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports.

T1571
Non-Standard Port
MalwareHiddenFace

HiddenFace's passive mode listens on TCP 47000.

T1571
Non-Standard Port
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used a custom binary protocol over TCP port 443 for C2.

T1571
Non-Standard Port
MalwareCyclops Blink

Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic.

T1571
Non-Standard Port
MalwareGoldenSpy

GoldenSpy has used HTTP over ports 9005 and 9006 for network traffic, 9002 for C2 requests, 33666 as a WebSocket, and 8090 to download files.

T1571
Non-Standard Port
MalwareHARDRAIN

HARDRAIN binds and listens on port 443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareMacMa

MacMa has used TCP port 5633 for C2 Communication.

T1571
Non-Standard Port
MalwarePoetRAT

PoetRAT used TLS to encrypt communications over port 143

T1571
Non-Standard Port
MalwareZxShell

ZxShell can use ports 1985 and 1986 in HTTP/S communication.

T1571
Non-Standard Port
MalwareSPAWNCHIMERA

SPAWNCHIMERA has the ability to bind on a localhost and listen on port 8300.

T1571
Non-Standard Port
MalwarenjRAT

njRAT has used port 1177 for HTTP C2 communications.

T1571
Non-Standard Port
MalwareVIRTUALPITA

VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098.

T1571
Non-Standard Port
ToolCovenant

Covenant listeners and controllers can be configured to use non-standard ports.

T1571
Non-Standard Port
ToolQuasarRAT

QuasarRAT can use port 4782 on the compromised host for TCP callbacks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.