UDP 16464
Synopsis
- ZeroAccess (aka Sirefef) malware used UDP/16464 for its peer-to-peer command-and-control/peer discovery; IDS signatures and incident reports commonly flag UDP/16464 traffic as ZeroAccess-related.
- Legitimate VoIP systems can also use UDP/16464 as an RTP media port, since many platforms allocate RTP from 16384–32767: for example, Asterisk (default 10000–20000), FreeSWITCH (16384–32768), and Cisco CUCM/phones (commonly 16384–32767) may place call audio on UDP/16464 during sessions.
Observed activity
Last 30 days
Detailed chart