TROJAN: SubSeven Scan Attempt
This signature detects TCP packets sent to TCP port 27374. This can indicate an attacker attempting to confirm installation of the Trojan SubSeven v2.2 on the system. SubSeven, a remote administration Trojan, allows attackers to access data and gain control over some functions on remote Microsoft Windows systems. This signature can sometimes trigger false-positives when legitimate services are running on port 27374.
Extended Description
SubSeven is a Trojan that allows remote attackers to gain full control over an infected machine.
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
8.8