TCP Port 6789 – radg

TCP Port 6789 – radg

About TCP Port 6789

Port 6789 is registered with the Internet Assigned Numbers Authority (IANA) for radg. The IANA description reads: ‘GSS-API for the Oracle Remote Administration Daemon’. This port is referenced in 16 IDS rules and exhibits moderate malware activity in monitored traffic.

IDS Rule References

16 IDS / security rules reference TCP port 6789. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 6): policy-violation (7), attempted-admin (2), trojan-activity (2), command-and-control (1), misc-activity (1), attempted-user (1).

Sample rule descriptions for TCP port 6789:

  • MALWARE-BACKDOOR Doly 2.0 access
  • SERVER-OTHER CHAT IRC topic overflow
  • POLICY-SOCIAL IRC nick change
  • SERVER-OTHER CHAT IRC Ettercap parse overflow attempt
  • POLICY-SOCIAL IRC message

Malware Activity

A meaningful share of monitored traffic on this port involves malware indicators.

5 of 16 IDS rules for TCP port 6789 involve malware activity.

Families observed (top 4): Doly (1), MAGICHOUND.MPK (1), Mirai (1), Siloscape (1).

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).

© 2002-2026 AuditMyPC.com