[Snort-users] Fwd: Re: Port: 27374 asp

Dragos Ruiu dr at ...50...
Sat Aug 19 01:25:38 EDT 2000

In case you didn't notice this... for the trojan rulesets.


----------  Forwarded Message  ----------
Subject: Re: Port: 27374 asp
Date: Fri, 18 Aug 2000 03:45:56 -0600
From: Max0r <max0r at ...347...>

Port 27374 is used by the latest (2.1) release of the Sub7 trojan.
This trojan infects windows 9x/NT hosts.
The main distribution site for Sub7 is, sub7.slak.org. I suggest
downloading the client, and trying to connect to yourself.
If you _can_ connect to yourself without a password, you can remove
the trojan with the click of a mouse. Otherwise, try your antivirus


dursec.com ltd. / kyx.net - we're from the future
pgp fingerprint: 18C7 E37C 2F94 E251 F18E  B7DC 2B71 A73E D2E8 A56D 
pgp key: http://www.dursec.com/drkey.asc

More information about the Snort-users mailing list