The 4307 Mirage
How one port anomaly exposed a much larger infrastructure.
Inside the investigation
Follow the investigation from an unusual concentration of traffic on port 4307 to a broader network of infrastructure, source IPs, and connected activity.
Download the full report
Complete the form to access the research.
One anomaly. Millions of observations.
What started as an unusual concentration of traffic on port 4307 quickly expanded into a much broader infrastructure investigation.
One host stood out
A single IP appeared in 29.5% of the collected sample records involving TCP port 4307.
Traffic records revealed
Pivoting on that host uncovered 12.9 million sampled traffic records across roughly 80 days.
Distinct source IPs
Nearly all were associated with consumer broadband or mobile networks.
Related Android apps
Verified CATMO, CATMOLIVE and VODTV samples shared a codebase, with several AV engines flagging them as Trojan-Proxy.
The anomaly was only the starting point.
The full investigation connects unusual port activity with a wider infrastructure footprint, large-scale source activity, and related Android applications — showing how a single observable can lead to a much broader threat picture.