Technique.View on attack.mitre.org
Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.
Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.
Rules on DetectionCode tagged with T1571.
| Rule | Level | Log source |
|---|---|---|
| Potentially Suspicious Malware Callback Communication | high | windows / network_connection |
| Potentially Suspicious Malware Callback Communication - Linux | high | linux / network_connection |
| Communication To Uncommon Destination Ports | medium | windows / network_connection |
| Suspicious DNS Z Flag Bit Set | medium | zeek / NULL |
| Testing Usage of Uncommonly Used Port | medium | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco NVM - Outbound Connection to Suspicious Port | Anomaly | NULL | Cisco Network Visibility Module Flow Data |
| Cisco Secure Firewall - Communication Over Suspicious Ports | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - File Download Over Uncommon Port | Anomaly | NULL | Cisco Secure Firewall Threat Defense File Event |
| Ollama Abnormal Network Connectivity | Anomaly | NULL | Ollama Server |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used port 4050 for C2 communications. |
| GroupAPT32 | An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration. |
| GroupAPT33 | APT33 has used HTTP over TCP ports 808 and 880 for command and control. |
| GroupContagious Interview | Contagious Interview has used TCP port 1224 for C2. |
| GroupDarkVishnya | DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2. |
| GroupEmber Bear | Ember Bear has used various non-standard ports for C2 communication. |
| GroupFIN7 | FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules. |
| GroupGamaredon Group | Gamaredon Group has used port 6856 for C2 communications. |
| Used by | Procedure example |
|---|---|
| MalwareBADCALL | BADCALL communicates on ports 443 and 8000 with a FakeTLS method. |
| MalwareBankshot | Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method. |
| MalwareBeaverTail | BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244. |
| MalwareBendyBear | BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2. |
| ToolCovenant | Covenant listeners and controllers can be configured to use non-standard ports. |
| MalwareCyclops Blink | Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic. |
| MalwareDerusbi | Derusbi has used unencrypted HTTP on port 443 for C2. |
| MalwareEmotet | Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008. |
| CampaignC0018 | During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2. |
| CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication. |
| CampaignKV Botnet Activity | KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity. |
| CampaignOperation Wocao | During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000. |
| CampaignQuad7 Activity | Quad7 Activity has used non-standard TCP ports – such as 7777, 11288, 63256, 63210, 3256, and 3556 for C2. |
| CampaignRedPenguin | During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.