logo

[Guest Diary] Malware Source Servers: The Threat of Attackers Using Ephemeral Ports as Service Ports to Upload Data, (Wed, Feb 26th)

ID: e46b9f72-1463-5f90-9eda-1056a037f010

STIX ID: report--e46b9f72-1463-5f90-9eda-1056a037f010

Feed Name: SANS ISC Diary

Threat Score
45/100

Date Published: 2025-02-26

Date Updated: 2026-04-19

...
...

The report documents an SSH brute-force that resulted in a successful login on a honeypot and a rapid attempt to retrieve a payload from 140.143.196.172 over an ephemeral HTTP port (60102) using curl, wget, and raw TCP. It highlights how attackers host malware on nonstandard ports to evade scanners (Shodan/GreyNoise), provides observed indicators (attacker IP 8.133.192.98 and host 140.143.196.172:60102), and recommends hardening controls such as stricter SSH authentication, outbound filtering, application firewalls, and targeted scanning tools (e.g., Censys ASM) to detect protocol/port anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.