TCP Port 4443 – pharos
About TCP Port 4443
Port 4443 is registered with the Internet Assigned Numbers Authority (IANA) for pharos. The IANA description reads: ‘Pharos’. This port is referenced in 4 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
4 IDS / security rules reference TCP port 4443. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 1): trojan-activity (4).
Sample rule descriptions for TCP port 4443:
- ET MALWARE Possible Dyre SSL Cert (fake state)
- ET MALWARE Possible Dyre SSL Cert M1 (L O)
- ET MALWARE Possible Dyre SSL Cert M2 (L CN)
- ET MALWARE Possible Dyre SSL Cert M3 (O CN)
Malware Activity
Some malware indicators are observed on this port.
4 of 4 IDS rules for TCP port 4443 involve malware activity.
Families observed (top 1): Dyre (4).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and MITRE ATT&CK (Apache 2.0).
