Backdoor Intruders
Table A-1 shows a list of known (as of this writing) ports and the backdoor viruses and Trojans that try to use these ports. Many of these may be old, but given that virus writers tend to reuse each other's code, tracking the historical viruses is important. This compiled list from www.sans.org/security-resources/idfaq/oddports.php and other sources is one you can cross reference if you believe you have been hacked.
PORT NUMBER | TROJAN NAME |
2 | Death |
20 | Senna Spy FTP server |
21 | Back Construction, Blade Runner, Doly Trojan, fore, Invisible FTP, Juggernaut 42, Larva, MotIv FTP, Net Administrator, Senna Spy FTP server, Traitor 21, WebEx, WinCrash |
22 | Shaft |
23 | Fire, HacKer, Tiny, Telnet, Server, TTS, Truva, Atl |
25 | Ajan, Antigen, Email, Password, Sender, EPS, EPS II, Gip, Gris, Happy99, Hpteam, mail, I love you, Kuang2, Magic, Horse, MBT |
31 | Agent 31, Hackers, Paradise, MastersParadise |
41 | Deep Throat, Foreplay or Reduced Foreplay |
48 | DRAT |
50 | DRAT |
59 | DMSetup |
79 | CDK, Firehotcker |
80 | AckCmd, BackEnd, CGI, Backdoor, Executor, Hooker, RingZero |
81 | RemoConChubo |
99 | Hidden Port |
110 | ProMail trojan |
113 | Identd, Invisible, Deamon, Kazimas |
119 | Happy99 |
121 | JammerKillah |
123 | Net, Controller |
133 | Farnaz |
142 | NetTaxi |
146 | Infector |
146 | (UDP) Infector |
170 | A-trojan |
180 | (TCP/UDP) amanda |
334 | Backage |
420 | Breach |
421 | TCP Wrappers, trojan |
456 | Hackers Paradise |
513 | Grlogin |
514 | RPC Backdoor |
Get CMS Security Handbook: The Comprehensive Guide for WordPress®, Joomla!®, Drupal™, and Plone® now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.