TCP Port 666 – doom

TCP Port 666 – doom

About TCP Port 666

Port 666 is registered with the Internet Assigned Numbers Authority (IANA) for doom. The IANA description reads: ‘doom Id Software’. This port is referenced in 6 IDS rules and exhibits high malware activity in monitored traffic.

IDS Rule References

6 IDS / security rules reference TCP port 666. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 3): trojan-activity (3), misc-activity (2), command-and-control (1).

Sample rule descriptions for TCP port 666:

  • MALWARE-BACKDOOR SatansBackdoor.2.0.Beta
  • MALWARE-BACKDOOR BackConstruction 2.1 Client FTP Open Request
  • MALWARE-BACKDOOR BackConstruction 2.1 Server FTP Open Reply
  • ET MALWARE ELF/BASHLITE CnC Activity (Response)
  • ET MALWARE Win32/SuperBOT CnC Checkin

Malware Activity

Malware activity is frequently observed on this port.

6 of 6 IDS rules for TCP port 666 involve malware activity.

Families observed (top 5): BackConstruction (2), ELF_BASHLITE (1), Reptile (1), SatansBackdoor.2.0.Beta (1), Win32_SuperBOT (1).

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).

© 2002-2026 AuditMyPC.com