TCP Port 9002 – dynamid

TCP Port 9002 – dynamid

About TCP Port 9002

Port 9002 carries the IANA assignment for dynamid. The IANA description reads: ‘DynamID authentication’. This port is referenced in 2039 IDS rules and exhibits moderate malware activity in monitored traffic.

IDS Rule References

2039 IDS / security rules reference TCP port 9002. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 6): trojan-activity (728), web-application-activity (476), web-application-attack (344), attempted-recon (270), misc-activity (77), attempted-user (58).

Sample rule descriptions for TCP port 9002:

  • SERVER-WEBAPP PCCS mysql database admin tool access
  • POLICY-OTHER HP JetDirect LCD modification attempt
  • SERVER-WEBAPP HyperSeek hsx.cgi directory traversal attempt
  • SERVER-WEBAPP SWSoft ASPSeek Overflow attempt
  • SERVER-WEBAPP Progress webspeed access

Malware Activity

A meaningful share of monitored traffic on this port involves malware indicators.

681 of 2039 IDS rules for TCP port 9002 involve malware activity.

Families observed (top 8): Bancos (20), Fareit (15), Zeus (15), DesertFalcon (11), Symmi (11), Zebrocy (11), Chopper (10), Locky (9), and 262 more families.

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).

© 2002-2026 AuditMyPC.com