Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp DarkFTP [trojan] Dark FTP
tcp WinSatan [trojan] WinSatan
tcp Trinity [trojan] Trinity
tcp TheThing [trojan] The Thing (modified)
tcp SubSeven [trojan] SubSeven
tcp Subseven2.1.4DefCon8 [trojan] Subseven 2.1.4 DefCon 8
tcp ScheduleAgent [trojan] ScheduleAgent
tcp Moses [trojan] Moses
tcp Maniacrootkit [trojan] Maniac rootkit
tcp kaitex Kaitex Trojan
tcp ircu IRCU
tcp irc Internet Relay Chat
tcp EGO [trojan] EGO
udp Tuya IOT Tuya Discovery for IoT Devices
Top IPs Scanning
Today Yesterday
104.234.115.174 (10)194.180.49.112 (41)
104.234.115.128 (9)115.231.78.11 (15)
104.234.115.199 (9)199.45.154.115 (15)
143.42.164.127 (9)115.231.78.14 (12)
170.187.165.130 (8)206.168.35.185 (12)
143.42.1.185 (7)167.94.138.204 (12)
143.42.173.101 (6)104.156.155.3 (12)
45.79.114.248 (6)143.42.0.20 (12)
104.234.115.68 (6)167.94.146.24 (11)
45.33.105.182 (6)207.90.244.24 (11)
User Comments
Submitted By Date
Comment
2025-01-01 18:12:01
IoT devices based on the Tuya platform are using broadcast packets to port 6667 for autodiscovery.
2010-06-18 02:32:27
Lots of activity on this port over the last 3 days... could indicate a new worm scanning for IRC servers?
2005-08-03 07:27:57
Also used by MSN online games, reference http://zone.msn.com/en/support/article/support3426.htm
Deb Hale 2004-01-15 03:58:20
This port is used in conjunction with ports 901,902,903 by the Net-Devil virus.
Alex 2003-01-31 19:32:00
Be aware, this port is used by the W32.Netspree.Worm, see www.symantec.com and search for the worm. (NAV don't always pick it up...)
CVE Links
CVE # Description