TCP Port 9100 – hp-pdl-datastr
About TCP Port 9100
The Internet Assigned Numbers Authority (IANA) registers port 9100 for hp-pdl-datastr. The IANA description reads: ‘PDL Data Streaming Port’. This port is referenced in 4 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
4 IDS / security rules reference TCP port 9100. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 3): command-and-control (2), attempted-admin (1), misc-activity (1).
Sample rule descriptions for TCP port 9100:
- POLICY-OTHER HP JetDirect LCD modification attempt
- ET MALWARE Win32/Recslurp.D C2 Request (no alert)
- ET MALWARE Win32/Recslurp.D C2 Response
- ET EXPLOIT HP Printer Attempted Path Traversal via PJL
Malware Activity
Some malware indicators are observed on this port.
2 of 4 IDS rules for TCP port 9100 involve malware activity.
Families observed (top 1): Win32_Recslurp_D (2).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).
