Port 6667: Internet Relay Chat (plaintext)
Port 6667 is the customary plaintext port for Internet Relay Chat servers. RFC 7194 states that IRC networks have defaulted to TCP 6667 for plaintext connections, under the IANA ircu assignment of ports 6665 to 6669. The registered IRC port is 194, and TLS connections use 6697.
Port Details
Security Exposure
Connections on 6667 are plain text, so messages and passwords sent with the IRC PASS command cross the network unencrypted. IRC is also used as a command and control channel: MITRE ATT&CK lists Hildegard, Magic Hound malware, Siloscape and TeamTNT using IRC for C2, and Shadowserver publishes a report of IRC networks contacted by sandboxed malware.
Hardening
- +Block outbound TCP 6665 to 6669 from servers and workstations that have no need for IRC.
- +Use TLS on port 6697 for legitimate IRC use.
- +Require server and channel passwords on internal IRC services and keep the IRC daemon patched.
Monitoring
Alert on outbound connections to TCP 6665 to 6669 and on IRC commands such as NICK, USER and JOIN seen on non-standard ports.
Tools for Auditing and Monitoring IRC
Snort
Open SourceOpen-source network intrusion detection and prevention engine that inspects traffic with rule-based signatures and protocol analysis.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Threat intelligence platforms, IOC sharing communities, and STIX/TAXII tooling for collecting and distributing threat data.
Frequently Asked Questions
Is IRC on port 6667 encrypted?→
No. RFC 7194 describes 6667 as the plaintext default and 6697 as the port for IRC over TLS.
Why does port 6667 show up in malware analysis?→
Malware families have used IRC for command and control, and Shadowserver tracks IRC servers contacted by malware in sandboxes.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 6667 is not guaranteed to be IRC. Exploited-in-the-wild data from the CISA KEV catalog (CC0).