TCP Port 79 – finger
About TCP Port 79
The Internet Assigned Numbers Authority (IANA) registers port 79 for finger. The IANA description reads: ‘Finger’. This port is referenced in 16 IDS rules and exhibits moderate malware activity in monitored traffic.
IDS Rule References
16 IDS / security rules reference TCP port 79. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 6): attempted-recon (10), attempted-user (2), trojan-activity (1), misc-activity (1), attempted-admin (1), attempted-dos (1).
Sample rule descriptions for TCP port 79:
- MALWARE-BACKDOOR CDK
- PROTOCOL-FINGER cmd_rootsh backdoor attempt
- PROTOCOL-FINGER account enumeration attempt
- PROTOCOL-FINGER search query
- PROTOCOL-FINGER root query
Malware Activity
A meaningful share of monitored traffic on this port involves malware indicators.
2 of 16 IDS rules for TCP port 79 involve malware activity.
Families observed (top 2): CastleLoader (1), CDK (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).
