UDP Port 80 – HTTP (Hypertext Transfer Protocol)
About UDP Port 80
Port 80 carries the IANA assignment for http. The IANA description reads: ‘World Wide Web HTTP’. This port is referenced in 2 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
2 IDS / security rules reference UDP port 80. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 1): trojan-activity (2).
Sample rule descriptions for UDP port 80:
- ET MALWARE Win32/PlugX Variant CnC Activity
- ET MALWARE BPFDoor V2 UDP Magic Packet Inbound
Malware Activity
Some malware indicators are observed on this port.
2 of 2 IDS rules for UDP port 80 involve malware activity.
Families observed (top 2): BPFDoor (1), Win32_DLOADR_TIOIBEPQ (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
