Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: Port 6667 (tcp/udp) Attack Activity - SANS Internet Storm Center Port 6667 (tcp/udp) Attack Activity

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Port Information
Protocol Service Name
tcp DarkFTP [trojan] Dark FTP
tcp Trinity [trojan] Trinity
tcp TheThing [trojan] The Thing (modified)
tcp SubSeven [trojan] SubSeven
tcp Subseven2.1.4DefCon8 [trojan] Subseven 2.1.4 DefCon 8
tcp ScheduleAgent [trojan] ScheduleAgent
tcp Moses [trojan] Moses
tcp Maniacrootkit [trojan] Maniac rootkit
tcp kaitex Kaitex Trojan
tcp ircu IRCU
tcp irc Internet Relay Chat
tcp EGO [trojan] EGO
tcp WinSatan [trojan] WinSatan
[get complete service list]
User Comments
Submitted By Date
2010-06-18 02:32:27
Lots of activity on this port over the last 3 days... could indicate a new worm scanning for IRC servers?
2005-08-03 07:27:57
Also used by MSN online games, reference
Deb Hale 2004-01-15 03:58:20
This port is used in conjunction with ports 901,902,903 by the Net-Devil virus.
Alex 2003-01-31 19:32:00
Be aware, this port is used by the W32.Netspree.Worm, see and search for the worm. (NAV don't always pick it up...)
Add a comment
CVE Links
CVE # Description