TROJAN: SubSeven Scan Attempt

This signature detects TCP packets sent to TCP port 27374. This can indicate an attacker attempting to confirm installation of the Trojan SubSeven v2.2 on the system. SubSeven, a remote administration Trojan, allows attackers to access data and gain control over some functions on remote Microsoft Windows systems. This signature can sometimes trigger false-positives when legitimate services are running on port 27374.

Extended Description

SubSeven is a Trojan that allows remote attackers to gain full control over an infected machine.

Short Name
TROJAN:SUBSEVEN:SCAN
Severity
Warning
Recommended
False
Recommended Action
None
Category
TROJAN
Keywords
Attempt CVE-1999-0660 Scan SubSeven
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/27374
False Positive
Occasionally
CVSS Score

8.8

Found a potential security threat?