TCP Port 5222 – xmpp-client
About TCP Port 5222
Port 5222 carries the IANA assignment for xmpp-client. The IANA description reads: ‘XMPP Client Connection’. This port is referenced in 4 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
4 IDS / security rules reference TCP port 5222. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 2): bad-unknown (3), command-and-control (1).
Sample rule descriptions for TCP port 5222:
- ET MALWARE W32/Jabberbot.A Trednet XMPP CnC Beacon
- ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
- ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)
- ET EXPLOIT FREAK Weak Export Suite From Server (CVE-2015-0204)
Malware Activity
Some malware indicators are observed on this port.
1 of 4 IDS rules for TCP port 5222 involve malware activity.
Families observed (top 1): Jabberbot (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and MITRE ATT&CK (Apache 2.0).
