Port 27374Sub7

Port 27374 is notoriously associated with Sub7, a popular remote administration trojan from the late 1990s and early 2000s. Sub7 enables a malicious actor to gain covert control of infected Windows machines, allowing unauthorized access, data theft, and remote manipulation. Although its prevalence has declined, the port remains a common scan target for cybercriminals attempting to identify backdoored systems..

transport
unknown

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
4,711

rank 948 of 993 · top 95%

Technical Details

what runs on :27374

Sub7 (SubSeven) is a remote access trojan (RAT) historically used to exploit vulnerabilities in Windows operating systems. Once a victim mistakenly executes the malware payload, it installs itself stealthily and opens a backdoor listening on port 27374 by default. This allows attackers to bypass firewall protections and establish unauthorized remote sessions.

The Sub7 client program provides an intuitive graphical interface, enabling the attacker to execute a wide variety of malicious actions such as keystroke logging, file transfers, webcam activation, screenshot capture, and registry edits. Its modular architecture and plugin support further expanded its capabilities, making it a versatile but dangerous tool.

Over time, variants of Sub7 introduced evasion techniques including polymorphic code and encryption of traffic, complicating network detection. However, modern antivirus solutions and Windows security enhancements have reduced the effectiveness of classic Sub7 strains, even though port 27374 continues to be probed by attackers looking for old infections.

Security Information

exposure of :27374

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.8 across 216 ports — this one sits 0.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

unknown

every listening transport is another surface to filter at the edge

security overview

Sub7 open on port 27374 means the potential presence of one of the most well-known remote access trojans. Common vulnerabilities include:

  • Backdoors installed through social engineering, phishing, or malware bundles
  • Weak or absent endpoint protection allowing payload execution
  • Unpatched systems susceptible to privilege escalation

Mitigations include:

  • Blocking inbound/outbound connections on port 27374 at firewalls
  • Using up-to-date anti-malware to detect and remove RAT components
  • Training users to avoid suspicious attachments or downloads
  • Regular patching of operating systems and applications
  • Conducting network scans to identify unauthorized accessible services
  • Employing endpoint detection and response (EDR) solutions for ongoing monitoring

the 8 most looked-up other ports in security — 216 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted