Skip to content
  Threat research

The 4307 Mirage

How one port anomaly exposed a much larger infrastructure.

Inside the investigation

Follow the investigation from an unusual concentration of traffic on port 4307 to a broader network of infrastructure, source IPs, and connected activity.

Download the full report

Complete the form to access the research.

 
Key findings

One anomaly. Millions of observations.

What started as an unusual concentration of traffic on port 4307 quickly expanded into a much broader infrastructure investigation.

29.5%

One host stood out

A single IP appeared in 29.5% of the collected sample records involving TCP port 4307.

12.9M

Traffic records revealed

Pivoting on that host uncovered 12.9 million sampled traffic records across roughly 80 days.

162,908

Distinct source IPs

Nearly all were associated with consumer broadband or mobile networks.

3

Related Android apps

Verified CATMO, CATMOLIVE and VODTV samples shared a codebase, with several AV engines flagging them as Trojan-Proxy.

Why it matters

The anomaly was only the starting point.

The full investigation connects unusual port activity with a wider infrastructure footprint, large-scale source activity, and related Android applications — showing how a single observable can lead to a much broader threat picture.