Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp SubSeven [trojan] SubSeven
tcp BadBlood [trojan] Bad Blood
tcp Ttfloader [trojan] Ttfloader
tcp TheSaint [trojan] The Saint
tcp SubSevenMuie [trojan] SubSeven Muie
tcp SubSeven2.2 [trojan] SubSeven 2.2
tcp SubSeven2.1Gold [trojan] SubSeven 2.1 Gold
tcp Subseven2.1.4DefCon8 [trojan] Subseven 2.1.4 DefCon 8
tcp Seeker [trojan] Seeker
tcp Ramen [trojan] Ramen
tcp Lion [trojan] Lion
tcp FakeSubSeven [trojan] Fake SubSeven
tcp EGO [trojan] EGO
tcp Webhead [trojan] Webhead
Top IPs Scanning
Today Yesterday
64.39.106.60 (4)79.110.62.185 (11)
45.132.1.242 (2)64.39.106.39 (8)
91.240.118.215 (2)204.10.53.162 (4)
165.154.51.90 (2)217.102.255.188 (2)
103.89.89.85 (1)2.57.122.75 (2)
152.32.183.27 (1)152.32.252.233 (2)
124.225.167.213 (1)165.154.10.187 (2)
152.32.148.140 (1)152.32.183.27 (2)
Port diary mentions
URL
Jabber.Org r00t discovered, Vulnerabilities affect Koffice, Kdegraphics, xpdf viewer, Gpdf, Cups, and Tetex
User Comments
Submitted By Date
Comment
Saint Joesph Grimm 2009-10-04 18:45:22
ACK... Cant we get rid of this thing? Sub7 in a trojan that can be downloaded through any executable file (.exe) It is sometimes disquised as games, movies, self-extracting zip files. After opening the .exe the server will melt into the target system, making it hard to find. The server can be set to open on any number of ports... Most common are 27374, and 1243. Remote users then open an executable on their PC, that will grant them access to the server. Once this is done the Remote PC has ABSOLUTE CONTROL OF YOUR COMPUTOR!!!! I have seen this thing do things to computers remotely that even people sitting at them cannot do... Features include: Key Logger, ICQ Hijacker, Matrix style chat enableing, and basically anything you can control from your PC. Norton Antivirus can find and delete this trojan... I may have left alot out, but you get the clue.... Good Luck, I hope we can get rid of this one soon.... Oh, heres an extra little tidbit... anyone who is using sub7 is definatly trojaned themselves, the wonderful maker of this horse (Mobman of www.subseven.ws) has released all versions of this tool with the trojan enabled on it. So as soon as a would be hacker opens the "subseven.exe" they themselves become infected. !-D St Joesph Grimm
CVE Links
CVE # Description