TCP Port 6917
About TCP Port 6917
Port 6917 sits outside of IANA’s formally registered assignments. Ports in this numerical range can be assigned by IANA but this specific port has no current registration. It is referenced in 12 IDS rules and exhibits moderate malware activity indicators. Ports outside formal IANA assignment are commonly used by malware authors and security tooling.
IDS Rule References
12 IDS / security rules reference TCP port 6917. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 5): policy-violation (7), trojan-activity (2), command-and-control (1), attempted-user (1), misc-attack (1).
Sample rule descriptions for TCP port 6917:
- SERVER-OTHER CHAT IRC topic overflow
- POLICY-SOCIAL IRC nick change
- SERVER-OTHER CHAT IRC Ettercap parse overflow attempt
- POLICY-SOCIAL IRC message
- POLICY-SOCIAL IRC DCC file transfer request
Malware Activity
A meaningful share of monitored traffic on this port involves malware indicators.
3 of 12 IDS rules for TCP port 6917 involve malware activity.
Families observed (top 2): MAGICHOUND.MPK (1), Siloscape (1).
Data Sources
This information is compiled from: Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
