T1571 Non-Standard Port — ATT&CK Technique
Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data. Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.
Detection coverage (9)
- Potentially Suspicious Malware Callback Communication - Linux high
- Suspicious DNS Z Flag Bit Set medium
- Communication To Uncommon Destination Ports medium
- Potentially Suspicious Malware Callback Communication high
- Testing Usage of Uncommonly Used Port medium
- Ollama Abnormal Network Connectivity
- Cisco NVM - Outbound Connection to Suspicious Port
- Cisco Secure Firewall - Communication Over Suspicious Ports
- Cisco Secure Firewall - File Download Over Uncommon Port
Malware using this technique
- Hannotog
- PingPull
- Emotet
- GlassWorm
- StrongPity
- PoetRAT
- GoldenSpy
- Covenant
- SUGARUSH
- HiddenFace
- Raspberry Robin
- WellMail
- HOPLIGHT
- ZxShell
- MoonWind
- HARDRAIN
- Pikabot
- OSX_OCEANLOTUS.D
- SystemBC
- Metamorfo
- BendyBear
- BeaverTail
- njRAT
- SPAWNCHIMERA
- BADCALL
- Sardonic
- MacMa
- Derusbi
- VIRTUALPIE
- RotaJakiro
- RTM
- TrickBot
- QuasarRAT
- PlugX
- InvisibleFerret
- TYPEFRAME
- VIRTUALPITA
- GravityRAT
- Bankshot
- RedLeaves
- Cyclops Blink