Analytics BIOC Low

Abnormal network communication through TOR using an uncommon port

Suspicious connection from a known TOR IP to an uncommon port.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071) Non-Standard Port (T1571)
Attacker's goals:

Attackers might use TOR IP combined with random ports.to hide C2 inbound communication from inside a host.

Investigative actions:

Investigate the network configuration related to the participating port. Investigate processes that were listening to that port.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Abnormal network communication through TOR using an uncommon port and App-id Low
  • Abnormal network communication through TOR using a suspicious port Low