TCP Port 5061 – sips
About TCP Port 5061
Port 5061 is registered with the Internet Assigned Numbers Authority (IANA) for sips. The IANA description reads: ‘SIP-TLS’. This port appears in 9 IDS rules and does not have notable malware activity indicators in our data.
IDS Rule References
9 IDS / security rules reference TCP port 5061. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 3): bad-unknown (5), attempted-recon (2), attempted-admin (2).
Sample rule descriptions for TCP port 5061:
- PROTOCOL-VOIP Possible SIP OPTIONS service information gathering attempt
- OS-OTHER Bash environment variable injection attempt
- ET SCAN NMAP SIP Version Detection Script Activity
- ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
- ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).
