The 4307 Mirage
How one port anomaly exposed a much larger infrastructure.
After two actively exploited TrueConf vulnerabilities put TCP port 4307 in the spotlight, Attaxion researchers examined existing traffic telemetry to see what else was hiding behind the signal.
What the investigation uncovered
Download the full report
Get the complete investigation, evidence, methodology, and observables.
One anomaly. Millions of observations.
What started as an unusual concentration of traffic on port 4307 quickly expanded into a much broader infrastructure investigation.
One host stood out
A single IP appeared in 29.5% of the collected sample records involving TCP port 4307.
Traffic records revealed
Pivoting on that host uncovered 12.9 million sampled traffic records across roughly 80 days.
Distinct source IPs
Nearly all were associated with consumer broadband or mobile networks.
Related Android apps
Verified CATMO, CATMOLIVE and VODTV samples shared a codebase, with several AV engines flagging them as Trojan-Proxy.
The anomaly was only the starting point.
The full investigation connects unusual port activity with a wider infrastructure footprint, large-scale source activity, and related Android applications — showing how a single observable can lead to a much broader threat picture.