TCP Port 4443 – pharos

TCP Port 4443 – pharos

About TCP Port 4443

Port 4443 is registered with the Internet Assigned Numbers Authority (IANA) for pharos. The IANA description reads: ‘Pharos’. This port is referenced in 4 IDS rules and exhibits low malware activity in monitored traffic.

IDS Rule References

4 IDS / security rules reference TCP port 4443. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 1): trojan-activity (4).

Sample rule descriptions for TCP port 4443:

  • ET MALWARE Possible Dyre SSL Cert (fake state)
  • ET MALWARE Possible Dyre SSL Cert M1 (L O)
  • ET MALWARE Possible Dyre SSL Cert M2 (L CN)
  • ET MALWARE Possible Dyre SSL Cert M3 (O CN)

Malware Activity

Some malware indicators are observed on this port.

4 of 4 IDS rules for TCP port 4443 involve malware activity.

Families observed (top 1): Dyre (4).

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and MITRE ATT&CK (Apache 2.0).

© 2002-2026 AuditMyPC.com