TCP Port 6978
About TCP Port 6978
Port 6978 has no formal IANA registration. Ports in this numerical range can be assigned by IANA but this specific port has no current registration. It is referenced in 12 IDS rules and exhibits moderate malware activity indicators. Ports outside formal IANA assignment are commonly used by malware authors and security tooling.
IDS Rule References
12 IDS / security rules reference TCP port 6978. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 5): policy-violation (7), trojan-activity (2), command-and-control (1), attempted-user (1), misc-attack (1).
Sample rule descriptions for TCP port 6978:
- SERVER-OTHER CHAT IRC topic overflow
- POLICY-SOCIAL IRC nick change
- SERVER-OTHER CHAT IRC Ettercap parse overflow attempt
- POLICY-SOCIAL IRC message
- POLICY-SOCIAL IRC DCC file transfer request
Malware Activity
A meaningful share of monitored traffic on this port involves malware indicators.
3 of 12 IDS rules for TCP port 6978 involve malware activity.
Families observed (top 2): MAGICHOUND.MPK (1), Siloscape (1).
Data Sources
This information is compiled from: Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
