Tuesday, November 9, 2021

Traffic on unusual port

Apologies if this isn’t the most appropriate place to ask. We’re seeing a significant spike in traffic on port 61616. A quick search shows it’s generally used by ActiveMQ “An open source message broker written in Java…Communication is managed with features such as computer clustering and ability to use any DB as a JMS persistence provider besides virtual memory, cache, and journal persistency”

Sounds kinda like malware to me. Are there other uses for port 61616 or is it reasonable to see a spike in traffic on this port?



No comments:

Post a Comment