TCP Port 5555 – personal-agent
About TCP Port 5555
Port 5555 carries the IANA assignment for personal-agent. The IANA description reads: ‘Personal Agent’. This port is referenced in 3 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
3 IDS / security rules reference TCP port 5555. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 1): trojan-activity (3).
Sample rule descriptions for TCP port 5555:
- ET EXPLOIT Remote Command Execution via Android Debug Bridge
- ET EXPLOIT Remote Command Execution via Android Debug Bridge 2
- ET MALWARE zgRAT / PureLogs Stealer GZIP Exfiltration Outbound
Malware Activity
Some malware indicators are observed on this port.
1 of 3 IDS rules for TCP port 5555 involve malware activity.
Families observed (top 2): PureLogs_Stealer (1), zgRAT (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry and Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range).
