TCP Port 6790 – hnmp
About TCP Port 6790
The Internet Assigned Numbers Authority (IANA) registers port 6790 for hnmp. The IANA description reads: ‘HNMP’. This port is referenced in 13 IDS rules and exhibits moderate malware activity in monitored traffic.
IDS Rule References
13 IDS / security rules reference TCP port 6790. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 6): policy-violation (7), trojan-activity (2), command-and-control (1), attempted-user (1), misc-attack (1), denial-of-service (1).
Sample rule descriptions for TCP port 6790:
- SERVER-OTHER CHAT IRC topic overflow
- POLICY-SOCIAL IRC nick change
- SERVER-OTHER CHAT IRC Ettercap parse overflow attempt
- POLICY-SOCIAL IRC message
- POLICY-SOCIAL IRC DCC file transfer request
Malware Activity
A meaningful share of monitored traffic on this port involves malware indicators.
3 of 13 IDS rules for TCP port 6790 involve malware activity.
Families observed (top 2): MAGICHOUND.MPK (1), Siloscape (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
