TCP Port 5222 – xmpp-client

TCP Port 5222 – xmpp-client

About TCP Port 5222

Port 5222 carries the IANA assignment for xmpp-client. The IANA description reads: ‘XMPP Client Connection’. This port is referenced in 4 IDS rules and exhibits low malware activity in monitored traffic.

IDS Rule References

4 IDS / security rules reference TCP port 5222. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 2): bad-unknown (3), command-and-control (1).

Sample rule descriptions for TCP port 5222:

  • ET MALWARE W32/Jabberbot.A Trednet XMPP CnC Beacon
  • ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
  • ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)
  • ET EXPLOIT FREAK Weak Export Suite From Server (CVE-2015-0204)

Malware Activity

Some malware indicators are observed on this port.

1 of 4 IDS rules for TCP port 5222 involve malware activity.

Families observed (top 1): Jabberbot (1).

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and MITRE ATT&CK (Apache 2.0).

© 2002-2026 AuditMyPC.com