Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Port 6667 (tcp/udp) Attack Activity - SANS Internet Storm Center Port 6667 (tcp/udp) Attack Activity


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp DarkFTP [trojan] Dark FTP
tcp Trinity [trojan] Trinity
tcp TheThing [trojan] The Thing (modified)
tcp SubSeven [trojan] SubSeven
tcp Subseven2.1.4DefCon8 [trojan] Subseven 2.1.4 DefCon 8
tcp ScheduleAgent [trojan] ScheduleAgent
tcp Moses [trojan] Moses
tcp Maniacrootkit [trojan] Maniac rootkit
tcp kaitex Kaitex Trojan
tcp ircu IRCU
tcp irc Internet Relay Chat
tcp EGO [trojan] EGO
tcp WinSatan [trojan] WinSatan
Top IPs Scanning
TodayYesterday
080.082.064.127 (13)107.170.192.103 (61)
120.052.152.017 (10)080.082.064.127 (50)
122.228.019.080 (7)120.052.152.015 (16)
125.064.094.210 (7)162.243.128.177 (13)
120.052.152.015 (4)107.170.237.161 (11)
185.142.236.035 (3)120.052.152.017 (11)
125.064.094.211 (2)005.188.210.046 (8)
071.006.199.023 (2)107.170.196.101 (8)
080.082.077.033 (2)125.064.094.214 (6)
205.205.150.003 (2)107.170.239.125 (6)
User Comments
Submitted By Date
Comment
2010-06-18 02:32:27
Lots of activity on this port over the last 3 days... could indicate a new worm scanning for IRC servers?
2005-08-03 07:27:57
Also used by MSN online games, reference http://zone.msn.com/en/support/article/support3426.htm
Deb Hale 2004-01-15 03:58:20
This port is used in conjunction with ports 901,902,903 by the Net-Devil virus.
Alex 2003-01-31 19:32:00
Be aware, this port is used by the W32.Netspree.Worm, see www.symantec.com and search for the worm. (NAV don't always pick it up...)
Add a comment
CVE Links
CVE # Description