Non-Standard Port

T1571

Technique.View on attack.mitre.org

About this technique

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.

Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.

Detection rules9

Rules on DetectionCode tagged with T1571.

Sigma5

RuleLevelLog source
Potentially Suspicious Malware Callback Communicationhighwindows / network_connection
Potentially Suspicious Malware Callback Communication - Linuxhighlinux / network_connection
Communication To Uncommon Destination Portsmediumwindows / network_connection
Suspicious DNS Z Flag Bit Setmediumzeek / NULL
Testing Usage of Uncommonly Used Portmediumwindows / ps_script

Splunk4

RuleTypeRiskData source
Cisco NVM - Outbound Connection to Suspicious PortAnomalyNULLCisco Network Visibility Module Flow Data
Cisco Secure Firewall - Communication Over Suspicious PortsAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - File Download Over Uncommon PortAnomalyNULLCisco Secure Firewall Threat Defense File Event
Ollama Abnormal Network ConnectivityAnomalyNULLOllama Server

Groups17

Software41

Show 17 more

Campaigns8

Procedure examples66

Groups17

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used port 4050 for C2 communications.

GroupAPT32

An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration.

GroupAPT33

APT33 has used HTTP over TCP ports 808 and 880 for command and control.

GroupContagious Interview

Contagious Interview has used TCP port 1224 for C2.

GroupDarkVishnya

DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2.

GroupEmber Bear

Ember Bear has used various non-standard ports for C2 communication.

GroupFIN7

FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules.

GroupGamaredon Group

Gamaredon Group has used port 6856 for C2 communications.

View all 17 groups examples

Software41

Used byProcedure example
MalwareBADCALL

BADCALL communicates on ports 443 and 8000 with a FakeTLS method.

MalwareBankshot

Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method.

MalwareBeaverTail

BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244.

MalwareBendyBear

BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2.

ToolCovenant

Covenant listeners and controllers can be configured to use non-standard ports.

MalwareCyclops Blink

Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic.

MalwareDerusbi

Derusbi has used unencrypted HTTP on port 443 for C2.

MalwareEmotet

Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S.

View all 41 software examples

Campaigns8

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008.

CampaignC0018

During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections.

CampaignC0032

During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2.

CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication.

CampaignKV Botnet Activity

KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity.

CampaignOperation Wocao

During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000.

CampaignQuad7 Activity

Quad7 Activity has used non-standard TCP ports – such as 7777, 11288, 63256, 63210, 3256, and 3556 for C2.

CampaignRedPenguin

During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default.

References3

  1. Fortinet Agent Tesla April 2018 Open source
    Zhang, X. (2018, April 05). Analysis of New Agent Tesla Spyware Variant. Retrieved November 5, 2018.
  2. Symantec Elfin Mar 2019 Open source
    Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.
  3. change_rdp_port_conti Open source
    The DFIR Report. (2022, March 1). "Change RDP port" #ContiLeaks. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.