TCP Port 1002
About TCP Port 1002
Port 1002 has no formal IANA registration. While most ports below 1024 are assigned to canonical services, this specific port has no current IANA registration. It is referenced in 4 IDS rules and exhibits low malware activity indicators. Ports outside formal IANA assignment are commonly used by malware authors and security tooling.
IDS Rule References
4 IDS / security rules reference TCP port 1002. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 2): trojan-activity (3), misc-activity (1).
Sample rule descriptions for TCP port 1002:
- MALWARE-BACKDOOR Infector 1.6 Client to Server Connection Request
- ET MALWARE upStage Residential Proxy CnC Checkin
- ET MALWARE upStage Residential Proxy CnC Response
- ET MALWARE upStage Proxy Heartbeat
Malware Activity
Some malware indicators are observed on this port.
4 of 4 IDS rules for TCP port 1002 involve malware activity.
Data Sources
This information is compiled from: Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range) and Snort Community Rules (GPLv2).
