UDP Port 8000 – irdmi
About UDP Port 8000
Port 8000 carries the IANA assignment for irdmi. The IANA description reads: ‘iRDMI’. This port is referenced in 2 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
2 IDS / security rules reference UDP port 8000. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 2): command-and-control (1), trojan-activity (1).
Sample rule descriptions for UDP port 8000:
- ET MALWARE Win32/Dostre CnC Activity
- ET MALWARE nspx30 Backdoor Trigger Response Observed
Malware Activity
Some malware indicators are observed on this port.
2 of 2 IDS rules for UDP port 8000 involve malware activity.
Families observed (top 2): nspx30 (1), Win32_Dostre (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
