ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1571×

17 examples

TechniqueUsed byProcedure example
T1571
Non-Standard Port
GroupAPT32

An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration.

T1571
Non-Standard Port
GroupMuddyWater

MuddyWater has used ports 8043 and 8848 for botnet C2 communication.

T1571
Non-Standard Port
GroupRedEcho

RedEcho has used non-standard ports such as TCP 8080 for HTTP communication.

T1571
Non-Standard Port
GroupGamaredon Group

Gamaredon Group has used port 6856 for C2 communications.

T1571
Non-Standard Port
GroupFIN7

FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules.

T1571
Non-Standard Port
GroupSandworm Team

Sandworm Team has used port 6789 to accept connections on the group's SSH server.

T1571
Non-Standard Port
GroupRocke

Rocke's miner connects to a C2 server using port 51640.

T1571
Non-Standard Port
GroupContagious Interview

Contagious Interview has used TCP port 1224 for C2.

T1571
Non-Standard Port
GroupDarkVishnya

DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2.

T1571
Non-Standard Port
GroupEmber Bear

Ember Bear has used various non-standard ports for C2 communication.

T1571
Non-Standard Port
GroupAPT-C-36

APT-C-36 has used port 4050 for C2 communications.

T1571
Non-Standard Port
GroupLazarus Group

Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches.

T1571
Non-Standard Port
GroupSilence

Silence has used port 444 when sending data about the system from the client to the server.

T1571
Non-Standard Port
GroupVelvet Ant

Velvet Ant has used random high number ports for PlugX listeners on victim devices.

T1571
Non-Standard Port
GroupWIRTE

WIRTE has used HTTPS over ports 2083 and 2087 for C2.

T1571
Non-Standard Port
GroupMagic Hound

Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP.

T1571
Non-Standard Port
GroupAPT33

APT33 has used HTTP over TCP ports 808 and 880 for command and control.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.