Skip to content

HTTP Service on Non-standard Port

It refers to a web server or website delivering HTTP or HTTPS content through ports other than the standard 80 (HTTP) and 443 (HTTPS). While this may be used for traffic isolation or internal applications, threat actors often utilize non-standard ports to evade detection by scanners, crawlers, and security monitoring tools.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'HTTP Service on Non-standard Port' mean in web or domain analysis?

It refers to a web server or website delivering HTTP or HTTPS content through ports other than the standard 80 (HTTP) and 443 (HTTPS). While this may be used for traffic isolation or internal applications, threat actors often utilize non-standard ports to evade detection by scanners, crawlers, and security monitoring tools.

Why it matters02

Why would a domain operate an HTTP service on a non-standard port?

Some domains intentionally host content on uncommon ports to prevent indexing by search engines or discovery by automated tools. These services are usually accessible only via direct links. This technique is frequently seen in phishing sites, gambling platforms, or malicious infrastructures designed to hide from public visibility.

How analysts use it03

Why is hosting HTTP services on non-standard ports considered suspicious?

Legitimate web services rarely use ports like 8081, 8443, 5000, or 1337. Attackers often host phishing kits, malware payloads, or command-and-control (C2) dashboards on such ports to bypass traditional security layers. The use of non-standard ports is therefore a strong indicator of potential malicious intent or stealthy operations.

Often paired with:alert_only
Evidence shape

What HTTP Service on Non-standard Port looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "unusual_http_port",
  "name": "HTTP Service on Non-standard Port",
  "group": "http_crawling_history",
  "subgroup": "web_behavior_structure",
  "direction": "malicious",
  "evidence": {
    "url_shortener_chain": false,
    "auto_refresh_seconds": null,
    "direct_ip_link": false,
    "browser_interaction_required": true
  }
}
See in API reference
Siblings

Peers in Web Behavior & Structure

7 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Injected Iframe

An injected iframe refers to an HTML frame embedded within a web page that loads content from an external or malicious d

MaliciousCore
Malicious Redirect Behavior

It refers to the automatic forwarding of a user or system request from one domain to another destination. Redirects can

MaliciousCore
Direct Connection to an IP Address

It refers to the action of accessing a resource using a direct IP address instead of a domain name. Threat actors often

Malicious
JavaScript-based Redirect

It refers to a redirect mechanism implemented within a webpage using JavaScript code instead of standard HTTP response h

Malicious
Show 3 more in Web Behavior & Structure
In the wild

See HTTP Service on Non-standard Port fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to HTTP Service on Non-standard Port. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.